Skip to content

Missing security policy prevents a responsible disclosure in case a security vulnerability is discovered #1011

Open
@quapka

Description

@quapka

Is your feature request related to a problem? Please describe.
There is no security policy set up for this project. Also, searching for security in the documentation yields 0 results.

Describe the solution you'd like
A security policy is set up, e.g. using GitHub Security Advisory. Also when creating a new issue there should be an option to report a security vulnerability that links to the policy.

Describe alternatives you've considered
One can look for/guess e-mails of trusted maintainers, but that is far from a good practice.

Additional context
None.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementImprovement of existing features or bugfix

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions