Skip to content

Document vulnerability disclosure mechanism #110

Description

@markhobson

The service should have a vulnerability disclosure mechanism. GDS recommend using security.txt.

This involves hosting a small text file on the service either at /security.txt or /.well-known/security.txt.

NCSC recommend that we use the cross-government vulnerability disclosure form.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions