Skip to content

Conversation

@jonchurch
Copy link
Member

This draft PR introduces a config.yml. See Github docs here.

As is, this PR does two things:

  • Forces users to choose from one of the available Issue templates (blank_issues_enabled: false)
  • Creates a link to Expressjs.com security policy section

Everything about this config is up for debate. Currently the linked page doesn't clearly state an email address, which is something we can address elsewhere.

@jonchurch
Copy link
Member Author

We can also point folks to the Node slack or other places with active q/a

Co-authored-by: Sebastian Beltran <bjohansebas@gmail.com>
@wesleytodd
Copy link
Member

@jonchurch anything holding this up or can we merge this?

Copy link
Member

@UlisesGascon UlisesGascon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hold it please! I will replace the link when the security policy is updated (STF part)

@UlisesGascon UlisesGascon self-assigned this Dec 20, 2024
@wesleytodd
Copy link
Member

We got the email setup today. Which PR were we pending on this so I can make sure to drop the new reporting email in?

Comment on lines +2 to +5
contact_links:
- name: Security Report
url: https://expressjs.com/en/resources/contributing.html#security-policies-and-procedures
about: Email security reports to the maintainer list serve
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

With the security.md file, we already have that option

image

Suggested change
contact_links:
- name: Security Report
url: https://expressjs.com/en/resources/contributing.html#security-policies-and-procedures
about: Email security reports to the maintainer list serve

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants