Comfy-Org / Comfy-Org/ComfyUI_frontend

Add SECURITY.md with vulnerability disclosure policy

Open
#11,071 0 comments 0 reactions 0 assignees View on GitHub
audit:essentials code-audit documentation effort:trivial priority:recommended
Dominant language
TypeScript
Stars
2k
Forks
699
Avg merge
1d 7h
Merged PRs (30d)
490

Description

## Recommendation

### 📋 Add Security Disclosure Policy

This is a public repo with thousands of users but no `SECURITY.md`. Contributors and security researchers don't know how to responsibly report security issues.

## What Was Found

- No `SECURITY.md` in repo root
- No `.github/SECURITY.md`
- GitHub displays a "No security policy" notice on the Security tab

## How to Fix

Create `SECURITY.md` with:
- Supported versions
- How to report vulnerabilities (email, GitHub security advisories)
- Expected response timeline
- Disclosure policy

GitHub provides a template via Settings → Code security → Security policy.

---
**Category:** Essentials | **Priority:** Recommended | **Effort:** Trivial
Part of #11022
_Filed by repo-audit skill_

┆Issue is synchronized with this [Notion page](https://www.notion.so/Issue-11071-Add-SECURITY-md-with-vulnerability-disclosure-policy-33e6d73d365081fbaabee4637af787e7) by [Unito](https://www.unito.io)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.