Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Request for maintainer to create and publish security.md and security policy. #6436

Merged
merged 1 commit into from
Oct 31, 2024

Conversation

octojedi
Copy link
Contributor

Request for maintainer to create and publish security.md and security policy. In order to see security vulnerabilities, CVEs, and fixes, please publish a security policy with information on how to submit vulnerabilities, how to track CVEs and what users can expect in terms of remediation of vulnerabilities.

@Aarebecca
Copy link
Contributor

Currently, given our project scope, a full SECURITY.md policy may not be essential.

@octojedi
Copy link
Contributor Author

Currently, given our project scope, a full SECURITY.md policy may not be essential.

It doesn't need to be a comprehensive security.md, but a lot of teams use, import, and fork your library. Currently there is no security policy in your github repo to indicate how someone would report a security vulnerability, that you acknowledge the vulnerability by issuing a CVE, and the expectation for users of your Open Source library of remediation. Without this, third party scanners can not alert users of your library as a dependency of any security issues.

Is security essential for your project?

@Aarebecca Aarebecca merged commit e689156 into antvis:v5 Oct 31, 2024
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants