Skip to content

[Feature]: Enable Security Policy and Private Vulnerability Reporting #440

@XlabAITeam

Description

@XlabAITeam

As a sandbox solution, it is essential to provide a secure channel for reporting potential security concerns. Implementing a formal security policy ensures that any future findings can be disclosed, discussed, and resolved privately before being made public, protecting both the project and its users.

Suggestions and Solutions:

  1. Add a SECURITY.md file: Define the process for reporting potential security issues.
  2. Enable Private Vulnerability Reporting: Turn on this feature in Settings to allow researchers to submit reports confidentially via GitHub (Ref: https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-security-and-analysis-settings-for-your-repository).
  3. Security Advisories: This will allow the project to coordinate security fixes and issue CVEs if necessary.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions