Note: This may be combined with or used by #30
Parse
- Publisher contact
- Support channel
- Security contact & VDP
- Check supplied meta & available APIs, e.g., https://patchstack.com/database/api/v2/vdp/elementor
- Check for
security.txt file in website's root or .well-known/ directories
- Check for
security.txt file in package's root directory
- Create
security.md file if missing
- If there is a single contributor to the package, they become the security contact
- Else if the publisher is an organization that we can parse a contact from use that
- Else the security contact is wordpress.org
- Append contact info to package-meta & build-meta per spec
Note: This may be combined with or used by #30
Parse
security.txtfile in website's root or .well-known/ directoriessecurity.txtfile in package's root directorysecurity.mdfile if missing