Skip to content

docs: add SECURITY.md with vulnerability reporting policy#116

Open
RehanAhmad25 wants to merge 1 commit into
Sitaram8472:mainfrom
RehanAhmad25:add/security
Open

docs: add SECURITY.md with vulnerability reporting policy#116
RehanAhmad25 wants to merge 1 commit into
Sitaram8472:mainfrom
RehanAhmad25:add/security

Conversation

@RehanAhmad25

Copy link
Copy Markdown
Contributor

Description

This PR adds a SECURITY.md file to the repository root. School Website currently has no defined security policy, leaving contributors and users with no safe, private channel to report vulnerabilities. This change establishes a responsible disclosure process following GitHub's recommended best practices.

Closes #114

Type of Change

  • 📝 Documentation update
  • 🔒 Security

Changes Made

  • Added SECURITY.md at the root of the repository
  • Added explicit contact details with maintainer profile link
  • Included expected response timeline for reported vulnerabilities
  • Outlined responsible disclosure policy with 30-day embargo period
  • Added OWASP external reference link

How Has This Been Tested?

Documentation-only change — no code was modified, no functional testing required.

  • Verified SECURITY.md renders correctly on GitHub
  • Confirmed GitHub Security tab now detects and displays the policy

Checklist

  • My code follows the existing code style of the project
  • I have performed a self-review of my own code
  • I have updated the documentation if needed
  • My changes do not introduce any new warnings or errors
  • I have linked the related issue

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security]: Add SECURITY.md to define vulnerability reporting process

1 participant