Skip to content

Add SECURITY.md#919

Merged
lrf141 merged 2 commits into
mainfrom
issues-918
Jun 16, 2026
Merged

Add SECURITY.md#919
lrf141 merged 2 commits into
mainfrom
issues-918

Conversation

@lrf141

@lrf141 lrf141 commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

Closed #918

Signed-off-by: Kento Takeuchi <kento-takeuchi@cybozu.co.jp>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a repository security policy document to clarify how to report vulnerabilities and what versions are supported, addressing the project need to avoid public disclosure of security issues (Issue #918).

Changes:

  • Introduces SECURITY.md with guidance on supported versions and reporting channel (GitHub private vulnerability reporting).
  • Documents what information reporters should include in vulnerability reports.
  • Sets expectations around coordinated disclosure and discourages scanner-only reports.

Comment thread SECURITY.md Outdated
Comment on lines +23 to +25
Instead, please report them privately through GitHub's
[private vulnerability reporting][gh-advisory] feature, which is the only channel
we accept vulnerability reports through:
Comment thread SECURITY.md
Comment on lines +31 to +34
Please do not publicly disclose the vulnerability, in whole or in part, without
the maintainers' prior consent. We ask that you give us a reasonable amount of
time to investigate and release a fix, and coordinate the timing of any public
disclosure with us.
Signed-off-by: Kento Takeuchi <kento-takeuchi@cybozu.co.jp>
Comment thread SECURITY.md
@yoheinbb

Copy link
Copy Markdown
Contributor

LGTM

@lrf141 lrf141 merged commit d650f74 into main Jun 16, 2026
22 checks passed
@lrf141 lrf141 deleted the issues-918 branch June 16, 2026 04:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Clarify the security policy

3 participants