Skip to content

docs: Add security policy for the Vega org#20

Merged
hydrosquall merged 2 commits intomainfrom
cameron.yick/create-security-advisory
Feb 3, 2025
Merged

docs: Add security policy for the Vega org#20
hydrosquall merged 2 commits intomainfrom
cameron.yick/create-security-advisory

Conversation

@hydrosquall
Copy link
Copy Markdown
Member

Motivation

  • Make it easy for researchers and engineers to have a safe path to reporting security vulnerabilities
  • Keep Vega and its dependents (Vega-Lite, vega-embed, altair, etc) secure

Changes

SECURITY.md Outdated

A Vega [maintainer](https://github.com/vega/.github/blob/main/project-docs/MAINTAINERS.md) will send a response indicating next steps in handling your report. After the initial reply, the team will keep you informed of the progress towards a fix and announcement, and may ask for additional information or guidance.

You can also report a vulnerability in Vega Javascript packages through the [npm contact form](https://www.npmjs.com/support) by selecting "I'm reporting a security vulnerability", or in Python packages through the [PyPI form](https://pypi.org/security/)
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's remove this

Copy link
Copy Markdown
Member Author

@hydrosquall hydrosquall Feb 2, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removing the NPM and PyPI parts makes sense to avoid splitting the reports up, handled here 6d95e77. Did you also mean to remove the part indicating who will follow up on the reports?

@hydrosquall hydrosquall marked this pull request as ready for review February 2, 2025 19:17
@hydrosquall hydrosquall requested a review from domoritz February 2, 2025 23:40
Copy link
Copy Markdown
Member

@domoritz domoritz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks good as is

@hydrosquall hydrosquall merged commit d1efc5d into main Feb 3, 2025
@hydrosquall hydrosquall deleted the cameron.yick/create-security-advisory branch February 3, 2025 20:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants