Skip to content

Add a SECURITY.md security policy - #3491

Open
alex-securedotcom wants to merge 1 commit into
inkeep:mainfrom
secure-workflows:add-security-policy
Open

Add a SECURITY.md security policy#3491
alex-securedotcom wants to merge 1 commit into
inkeep:mainfrom
secure-workflows:add-security-policy

Conversation

@alex-securedotcom

Copy link
Copy Markdown

Hi, thanks for maintaining this project.

I noticed the repository does not have a SECURITY.md yet, so GitHub shows no
security policy on the Security tab and there's no clear channel for reporting a
vulnerability. This PR adds a minimal one that points reporters at a private
channel instead of a public issue.

It is intentionally minimal: just the reporting channel. Response timelines,
scope, and any safe-harbour language are left for you to define as you see fit.
Feel free to adjust the contact address (I used the conventional
security@<domain>) or point it at GitHub's private vulnerability reporting.

Happy to tweak anything if this doesn't fit how you'd like to handle it.

@changeset-bot

changeset-bot Bot commented Jul 31, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: f364e1a

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@github-actions

Copy link
Copy Markdown
Contributor

Thanks for the contribution!

What happens next:

  • A maintainer will review your PR.
  • If you don't hear back within a few business days, please comment here to nudge our team.
  • This repository is maintained through an internal mirror. When your change is accepted, this PR will close automatically. Don't be alarmed when it closes — that's how it merges, and your authorship is preserved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant