-
Notifications
You must be signed in to change notification settings - Fork 980
docs: modernize security policy and vulnerability reporting #3660
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
| ### Responsible Disclosure Guidelines | ||
|
|
||
| We follow responsible disclosure practices: | ||
|
|
||
| - **Embargo Period**: We ask that you allow maintainers a reasonable amount of time to investigate and release a fix before public disclosure. | ||
| - **Credit**: We will acknowledge your discovery in security release notes (unless you prefer anonymity) | ||
| - **Coordination**: We will work with you to coordinate the disclosure and release timeline | ||
| - **No Public Issues**: Please do not create public GitHub issues or pull requests for security vulnerabilities | ||
| - **Confidentiality**: We treat all vulnerability reports with strict confidentiality | ||
|
|
||
| ### Security Release Process | ||
|
|
||
| When a security vulnerability is confirmed: | ||
|
|
||
| 1. A fix is developed and tested | ||
| 2. A security release is prepared | ||
| 3. Users are notified via security advisories | ||
| 4. The vulnerability is publicly disclosed only after the patch is released and available | ||
|
|
||
| Thank you for helping keep Augur secure! |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This process will need confirmation from the maintainers since a lot of this language commits us to doing things
9f2da60 to
af891ce
Compare
Signed-off-by: itz-sidd <siddhantofficial002@gmail.com>
e6c1651 to
ca1bfa8
Compare
ca1bfa8 to
154c3a5
Compare
SECURITY.md
Outdated
| ### Private Disclosure Process | ||
|
|
||
| If you discover a security vulnerability in Augur, please report it privately: | ||
| ### Private Disclosure Process |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
this change will make this heading be duplicated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for pointing that out. I've cleaned up the duplicate heading in SECURITY.md and ensured the text flows properly. I also updated the template with the guidance and AI disclosure we discussed earlier. Is the draft good now !
Signed-off-by: itz-sidd <siddhantofficial002@gmail.com>
154c3a5 to
57c70e8
Compare
Description
This draft PR proposes an update to SECURITY.md to:
Since security policy involves maintainer-level decisions, this PR is opened as a draft to facilitate discussion and refinement before finalizing implementation.
Open Questions for Maintainers
2.Is there a preferred dedicated security contact email address?
This PR fixes #3655
Notes for Reviewers
Signed commits