Comfy-Org / Comfy-Org/ComfyUI_frontend
Add SECURITY.md with vulnerability disclosure policy
- Dominant language
- TypeScript
- Stars
- 2k
- Forks
- 699
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 490
Description
## Recommendation
### 📋 Add Security Disclosure Policy
This is a public repo with thousands of users but no `SECURITY.md`. Contributors and security researchers don't know how to responsibly report security issues.
## What Was Found
- No `SECURITY.md` in repo root
- No `.github/SECURITY.md`
- GitHub displays a "No security policy" notice on the Security tab
## How to Fix
Create `SECURITY.md` with:
- Supported versions
- How to report vulnerabilities (email, GitHub security advisories)
- Expected response timeline
- Disclosure policy
GitHub provides a template via Settings → Code security → Security policy.
---
**Category:** Essentials | **Priority:** Recommended | **Effort:** Trivial
Part of #11022
_Filed by repo-audit skill_
┆Issue is synchronized with this [Notion page](https://www.notion.so/Issue-11071-Add-SECURITY-md-with-vulnerability-disclosure-policy-33e6d73d365081fbaabee4637af787e7) by [Unito](https://www.unito.io)
Contributor guide
Assessment
This issue has not been assessed yet.