Skip to content

docs: add SECURITY.md with vulnerability reporting policy - #772

Open
arnavgoel17 wants to merge 1 commit into
janavipandole:mainfrom
arnavgoel17:issue/760-add-security-policy
Open

docs: add SECURITY.md with vulnerability reporting policy#772
arnavgoel17 wants to merge 1 commit into
janavipandole:mainfrom
arnavgoel17:issue/760-add-security-policy

Conversation

@arnavgoel17

@arnavgoel17 arnavgoel17 commented Aug 25, 2026

Copy link
Copy Markdown

Description

Closes #760

Adds a SECURITY.md file at the repository root with a complete security policy.

What's included

  • Supported versions — documents that fixes target the latest main branch
  • Private reporting channels — GitHub private vulnerability reporting (preferred) and email fallback (the address already listed in CODE_OF_CONDUCT.md)
  • Responsible disclosure process — 5-step flow from report to coordinated public disclosure with contributor credit
  • Response timelines — acknowledgement within 72 hours, initial assessment within 7 days, fixes for high-severity issues within 30 days
  • Scope — in-scope (static site, server.js, auth/Firebase client flows, Docker/Vercel config) and out-of-scope items
  • Safe harbor — good-faith research protection

Validation

  • ✅ Follows GitHub's recommended security policy format
  • ✅ Email contact matches the one in CODE_OF_CONDUCT.md
  • ✅ Markdown-only change — no code touched, no build impact
  • ✅ Branch follows the repo convention from CONTRIBUTING.md (issue/760-add-security-policy)

…ure process

Adds a security policy covering private vulnerability reporting channels,
responsible disclosure process, response timelines, scope, and safe harbor
guidelines. Closes janavipandole#760
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

missing security documentation

1 participant