GSA / GSA/CFO.gov

Security Policy violation SECURITY.md

Open Beginner friendly
#1,234 85 comments 0 reactions 0 assignees View on GitHub
allstar-gsa
Dominant language
JavaScript
Stars
7
Forks
8
PR merge metrics
No merged PRs in 30d

Description

_This issue was automatically created by [Allstar](https://github.com/ossf/allstar/)._

**Security Policy Violation**
Security policy not enabled.
A SECURITY.md file can give users information about what constitutes a vulnerability and how to report one securely so that information about a bug is not publicly visible. Examples of secure reporting methods include using an issue tracker with private issue support, or encrypted email with a published key.

To fix this, add a SECURITY.md file that explains how to handle vulnerabilities found in your repository. Go to https://github.com/GSA/CFO.gov/security/policy to enable.

For more information, see https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository.

---

Issue created by [GSA Allstar](https://github.com/gsa/.allstar). See remediation hints in the [README](https://github.com/GSA/.allstar?tab=readme-ov-file#policy-configuration).

This issue will auto resolve when the policy is in compliance.

Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the repository's security policy page and the GitHub guidance linked in the issue. Add SECURITY.md with guidance on what constitutes a vulnerability and how to report one securely, then enable the repository security policy and confirm that the Allstar check resolves automatically.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.