Skip to content

add minimal security policy#203

Merged
PSeitz merged 1 commit intoPSeitz:mainfrom
Marcono1234:security-policy
Jan 28, 2026
Merged

add minimal security policy#203
PSeitz merged 1 commit intoPSeitz:mainfrom
Marcono1234:security-policy

Conversation

@Marcono1234
Copy link
Copy Markdown
Contributor

Resolves #199

To draw attention to the enabled "private vulnerability reporting" feature. Because unlike the SECURITY.md file which is prominently shown in a few places in the GitHub UI, the "private vulnerability reporting" feature can be difficult to find in case users are not aware that it exists.

Here are a few places where this SECURITY.md is shown:

  • Tab on the main page
    Screenshot main page
  • Sidebar
    Screenshot sidebar
  • When using issue templates and the user creates a new issue (does not apply here, since this repository does not use issue templates)

Feel free to adjust the policy file as you like though, for example:

  • mention things which are / are not considered vulnerabilities
    (maybe that is only needed if you get a lot of bogus reports)
  • mention the time frame in which users can expect a result, e.g. in case you are busy with other projects, so that users know that it can take a few days

To draw attention to the enabled "private vulnerability reporting" feature.
Because unlike the SECURITY.md file which is prominently shown in a few places
in the GitHub UI, the "private vulnerability reporting" feature can be difficult
to find in case users are not aware that it exists.
@PSeitz
Copy link
Copy Markdown
Owner

PSeitz commented Jan 28, 2026

Thanks!

@Marcono1234 Marcono1234 deleted the security-policy branch February 20, 2026 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add Security Policy file for reporting potential vulnerabilities

2 participants