Skip to content

Conversation

@Danielkis97
Copy link
Contributor

This PR suggests adding a short note recommending the use of PGP encryption for sensitive vulnerability reports submitted via email.

Currently, no public key is available, the note includes a suggestion to consider publishing one in the future to support secure disclosure.

This change is a small improvement to align with common security best practices and is meant as a contribution suggestion to improve the disclosure process.

Happy to revise or remove if the team prefers a different approach. Appreciate your work on Mitosis!

Added a short note recommending the use of PGP for sensitive security disclosures via email.

Currently, no public key is available – this change suggests publishing one to enable encrypted reports in the future.

This aligns with common industry security practices and improves the overall disclosure process.

This comment was marked as outdated.

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@riemannulus riemannulus requested a review from Copilot July 31, 2025 17:19
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds a recommendation for PGP encryption when submitting sensitive vulnerability reports via email. It acknowledges that no public key is currently available but suggests this as a security best practice for future consideration.

  • Adds a note recommending PGP encryption for sensitive vulnerability reports
  • Acknowledges the current lack of a public key while suggesting it as a future improvement

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@codecov
Copy link

codecov bot commented Jul 31, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@riemannulus riemannulus merged commit 4bf069b into mitosis-org:main Aug 7, 2025
10 checks passed
@riemannulus
Copy link
Contributor

🎉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants