Skip to content

BAH-4802 | Add SECURITY.md (vulnerability disclosure policy)#70

Open
vishalkarmalkarthoughtworks wants to merge 1 commit into
masterfrom
BAH-4802
Open

BAH-4802 | Add SECURITY.md (vulnerability disclosure policy)#70
vishalkarmalkarthoughtworks wants to merge 1 commit into
masterfrom
BAH-4802

Conversation

@vishalkarmalkarthoughtworks

Copy link
Copy Markdown
Contributor

Summary

Adds SECURITY.md at the repo root. Points security researchers to Bahmni's private vulnerability disclosure process — report to security@bahmni.org rather than via public issues/PRs — and links to the full process on the Bahmni wiki.

Part of the rollout tracked in BAH-4802. Template validated on bahmni-core#331. Thin by design: the wiki remains the canonical Bahmni security documentation; this file is an on-GitHub signpost to it.

Why

GitHub renders SECURITY.md as the repo's "Security policy" (Security tab) and surfaces it when someone opens an issue, giving researchers clear guidance to disclose privately. Satisfies the ch_security_policy check in the Bahmni OSS best-practices audit.

Test plan

  • SECURITY.md visible at repo root
  • Repo "Security" tab shows the policy
  • Links resolve (security@bahmni.org, wiki page)

Adds SECURITY.md at the repo root pointing reporters to the private Bahmni disclosure process (security@bahmni.org) and the full process on the wiki. Satisfies the ch_security_policy OSS-audit check.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant