Skip to content

Conversation

@ericwb
Copy link

@ericwb ericwb commented Apr 11, 2022

This change create a security policy that will effectively be the default for
all repos in the this org. The contents of this policy do not mention project
specific details so as to keep it generic enough to be used by any repository
in the org.

For more information on GitHub security policies, see:
https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository

This file serves as one of the default community health files for the org. Further details can
be found here:
https://docs.github.com/en/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file

This change create a security policy that will effectively be the default for
all repos in the this org. The contents of this policy do not mention project
specific details so as to keep it generic enough to be used by any repository
in the org.

For more information on GitHub security policies, see:
https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository

This file serves as one of the default community health files for the org. Further details can
be found here:
https://docs.github.com/en/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file
@ericwb ericwb added the documentation Improvements or additions to documentation label Apr 11, 2022
@jonasrosland
Copy link

Hi @ericwb ! It looks like this is taken mostly from the standard SECURITY.md that we're using from OSPO, is that correct?

One thing that stands out is line 15, " If you know of a publicly disclosed security vulnerability for this project, please IMMEDIATELY contact the maintainers of this project privately. The use of encrypted email is encouraged."
It's hard to use encrypted email if you don't know the receiving party's public key, which is why the security@vmware.com key is linked in the original doc. Previously we've had project leaders reach out to the security team to ensure that they are ready handle vulnerability disclosures for projects. Should we have some wording in there to make sure projects still apply for that, or are we defaulting to projects handling this themselves going forward?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants