Skip to content

docs: add security policy#8

Merged
JRemitz merged 1 commit intomainfrom
docs/security-policy
Apr 10, 2026
Merged

docs: add security policy#8
JRemitz merged 1 commit intomainfrom
docs/security-policy

Conversation

@JRemitz
Copy link
Copy Markdown
Contributor

@JRemitz JRemitz commented Apr 10, 2026

Summary

Adds SECURITY.md so GitHub renders a policy in the Security tab and checks off "Security policy" in Community Standards. Scope is tailored for a Google/YouTube OAuth plugin: token leakage, token file permissions, OAuth redirect/state handling, scope abuse. Out-of-scope: Google APIs and upstream google-auth libraries.

Follow-up

  • Enable Private Vulnerability Reporting under Settings → Code security.

Documents scope (OAuth token handling, scope abuse, redirect flow),
supported versions, and private vulnerability reporting channel so
GitHub surfaces a policy in the Security tab and Community Standards
checklist.
@JRemitz JRemitz merged commit 1afab19 into main Apr 10, 2026
5 checks passed
@JRemitz JRemitz deleted the docs/security-policy branch April 10, 2026 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant