Skip to content

Add email address for reporting security issues#2835

Merged
stevenengler merged 1 commit intoshadow:mainfrom
stevenengler:update-security-doc
Apr 4, 2023
Merged

Add email address for reporting security issues#2835
stevenengler merged 1 commit intoshadow:mainfrom
stevenengler:update-security-doc

Conversation

@stevenengler
Copy link
Copy Markdown
Contributor

Currently if you click github's "view security policy" button, it brings you to a page that says "Non-goal: Security", which probably isn't the best way to present our security policy :)

This PR adds a small section with an email address for people to report security issues. While we don't really care about the shadow code security specifically (the simulation runs arbitrary code anyways), we do care about things like if we accidentally checked-in a key to the repository, or if we have a security issue in our CI workflows, or if one of shadow's dependencies becomes malicious.

This copies the email address from the code of conduct.

@stevenengler stevenengler added this to the Documentation milestone Apr 3, 2023
@stevenengler stevenengler requested a review from sporksmith April 3, 2023 22:27
@stevenengler stevenengler self-assigned this Apr 3, 2023
@github-actions github-actions bot added the Component: Documentation In-repository documentation, under docs/ label Apr 3, 2023
@stevenengler stevenengler force-pushed the update-security-doc branch from 1474307 to 8340537 Compare April 4, 2023 16:15
@stevenengler stevenengler merged commit b00636e into shadow:main Apr 4, 2023
@stevenengler stevenengler deleted the update-security-doc branch April 4, 2023 18:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Component: Documentation In-repository documentation, under docs/

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants