Skip to content

docs: add SECURITY.md with coordinated-disclosure contact#394

Closed
JosefVacha wants to merge 1 commit into
AISecurityLab:mainfrom
JosefVacha:bounty/issue-392
Closed

docs: add SECURITY.md with coordinated-disclosure contact#394
JosefVacha wants to merge 1 commit into
AISecurityLab:mainfrom
JosefVacha:bounty/issue-392

Conversation

@JosefVacha

Copy link
Copy Markdown

Summary

Add SECURITY.md with coordinated-disclosure policy, supported versions table, reporting contact (ais@ai4i.it), and expected response SLA.

Root Cause

A security-testing toolkit without a SECURITY.md is a bad look and leaves researchers no canonical disclosure channel. The repository lacked a formal security policy document.

Proposed Changes

  • Created SECURITY.md at repo root with:
    • (a) Supported versions table
    • (b) Reporting contact (ais@ai4i.it)
    • (c) Expected response SLA (48h acknowledgement, 7-day assessment)
    • (d) Coordinated disclosure policy
  • Linked SECURITY.md from README.md (security badge)
  • Linked SECURITY.md from CONTRIBUTING.md (added security notice)

Verification Results

💎 Bounty Claims & Links

@JosefVacha JosefVacha closed this by deleting the head repository May 26, 2026
Comment thread SECURITY.md
| Version | Supported |
| ------- | ------------------ |
| Latest | :white_check_mark: |
| < 2.0 | :x: |

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Version is 0.9.1

Comment thread SECURITY.md

**Expected Response SLA:**
- **Acknowledgement:** Within 48 hours of receiving your report.
- **Initial Assessment:** Within 7 days with a detailed plan for addressing the issue.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

14 days

Comment thread SECURITY.md
**Expected Response SLA:**
- **Acknowledgement:** Within 48 hours of receiving your report.
- **Initial Assessment:** Within 7 days with a detailed plan for addressing the issue.
- **Status Updates:** Every 5 days until the vulnerability is resolved.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Every month

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants