Skip to content

[Repo] feat: Add security policy#20

Merged
finallyjay merged 1 commit intomainfrom
repo/add-security-policy
Apr 8, 2026
Merged

[Repo] feat: Add security policy#20
finallyjay merged 1 commit intomainfrom
repo/add-security-policy

Conversation

@finallyjay
Copy link
Copy Markdown
Owner

Summary

  • Adds SECURITY.md with instructions to report vulnerabilities via private advisory
  • Clarifies scope (repo configs only, not upstream images) and response timeline

Test plan

  • Verify it appears in GitHub's community profile
  • Verify the private advisory link works

Provides instructions for responsibly reporting
vulnerabilities via private advisory.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings April 8, 2026 15:45
@finallyjay finallyjay merged commit fed6a97 into main Apr 8, 2026
2 checks passed
@finallyjay finallyjay deleted the repo/add-security-policy branch April 8, 2026 15:45
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a repository security policy document to guide vulnerability reporting and clarify what is (and isn’t) in scope.

Changes:

  • Introduces SECURITY.md with guidance for responsible disclosure via GitHub private security advisories
  • Defines scope as repository Docker Compose/config files (not upstream images)
  • States a 72-hour initial response target and that only main is supported

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +8 to +10
**Do not open a public issue.** Instead, contact the
maintainer directly by email or through a
[private security advisory](https://github.com/finallyjay/selfhosted-docker-services/security/advisories/new).
Copy link

Copilot AI Apr 8, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The policy instructs reporters to contact the maintainer “directly by email”, but no email address (or pointer to where to find it) is provided. This makes the guidance incomplete/confusing; either add a dedicated security contact email (or reference a contact location), or remove the email path and direct users solely to GitHub Private Vulnerability Reporting.

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants