Skip to content

The project MUST publish the process for reporting vulnerabilities on the project site. #11

@SteveLasker

Description

@SteveLasker

From the OpenSSF Best Practice requirements:

  1. The project MUST publish the process for reporting vulnerabilities on the project site. (URL required)
  2. If private vulnerability reports are supported, the project MUST include how to send the information in a way that is kept private.

Example: https://github.com/helm/community/blob/main/SECURITY.md

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions