Skip to content

docs: add SECURITY.md with vulnerability reporting policy#279

Open
jackhax wants to merge 1 commit intosbmpost:masterfrom
jackhax:add-security-policy
Open

docs: add SECURITY.md with vulnerability reporting policy#279
jackhax wants to merge 1 commit intosbmpost:masterfrom
jackhax:add-security-policy

Conversation

@jackhax
Copy link

@jackhax jackhax commented Mar 7, 2026

Summary

  • Adds SECURITY.md to enable GitHub's native security features (private advisories, "Report a vulnerability" button)
  • Defines supported versions, scope/attack surfaces, and out-of-scope items
  • Provides clear private reporting instructions via GitHub Private Advisories
  • Includes user-facing guidance on safe installation and binary verification

Motivation

The repository currently has no security policy, which means:

  • GitHub shows a "No security policy detected" warning on the Security tab
  • There is no documented channel for responsible disclosure
  • Users have no guidance on verifying binary integrity

This PR addresses all three with a lightweight, project-appropriate policy.

🤖 Generated with Claude Code

Adds a security policy covering supported versions, scope/attack
surfaces, private reporting instructions, and user guidance for
safe installation.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant