-
Notifications
You must be signed in to change notification settings - Fork 20
DOC,SEC: Security Disclosure Guidelines #88
Comments
|
FWIW, from https://github.com/securitytxt/security-txt : Frequently asked questionsWhat is the main purpose of security.txt? The main purpose of security.txt is to help make things easier for companies and security researchers when trying to secure platforms. Thanks to security.txt, security researchers can easily get in touch with companies about security issues. Is security.txt an RFC? security.txt is currently an Internet draft that has been submitted for RFC review. This means that security.txt is still in the early stages of development. We welcome contributions from the public: https://github.com/securitytxt/security-txt Where should I put the security.txt file? For websites, the security.txt file should be placed under the |
@mgwalker this issue was closed. IMHO, there is still a case for:
|
Thanks @westurner! I agree with you about disclosure policies. However, this repo has been entirely unmaintained for quite a while, and I'm planning to archive it. For whatever reason, I don't have write access to this repo so I can't archive it yet, and then this issue got caught up in an automated stale issue closing script. Thanks again for your contribution, and especially for carrying this particular torch for so long! I wish I could say I knew how best to take this forward. Perhaps @konklone has ideas. |
NP. Is an updated resource for this now?
(... Also, SPDX is a good spec for code.gov to help push and pull: https://en.wikipedia.org/wiki/Software_Package_Data_Exchange ) |
re: maintainer guidelines and README_TEMPLATEs: It's a good idea to specifically mention what to do with security disclosures; and whether there is a bounty program. (And open source governance things like succession order and push privs/keys).
From "SEC: Add security disclosure process to developers page" pandas-dev/pandas#8545 :
Are there good examples of responsible disclosure guidelines?
The text was updated successfully, but these errors were encountered: