Skip to content

Add security policy#85

Open
heart-ktf wants to merge 1 commit into
maxcountryman:mainfrom
heart-ktf:add-security-policy
Open

Add security policy#85
heart-ktf wants to merge 1 commit into
maxcountryman:mainfrom
heart-ktf:add-security-policy

Conversation

@heart-ktf

@heart-ktf heart-ktf commented May 11, 2026

Copy link
Copy Markdown

Summary

  • add a root SECURITY.md with a documented vulnerability disclosure process
  • direct reporters to GitHub private vulnerability reporting instead of public issues or pull requests
  • include a fallback email address and the key details needed to triage a report

Why

Issue #84 asks for a clear responsible disclosure path so downstream users and security auditors can see how vulnerabilities should be reported without exposing them publicly.

This keeps the change minimal while still documenting where reports should go and what information helps with triage.

Closes #84

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Request: add SECURITY.md with vulnerability disclosure process

1 participant