Security Page
- Dominant language
- JavaScript
- Stars
- 353
- Forks
- 565
- Avg merge
- 7h 15m
- Merged PRs (30d)
- 5
Description
Cordova is currently missing a Security page at https://cordova.apache.org/security/ or similar where the process of reporting security bugs is documented, we just link to http://www.apache.org/security/ in the footer.
I suggest having a few sentences on the Cordova site itself, if only for better Google-ability.
The page could also list or link to previous CVEs:
https://cordova.apache.org/announcements/2015/11/20/security.html
https://www.cvedetails.com/vulnerability-list/vendor_id-45/product_id-27153/Apache-Cordova.html
Some examples:
https://nodejs.org/en/security/
https://www.ruby-lang.org/en/security/
Contributor guide
Research direction
Start by inspecting the Cordova docs site structure and its footer, then compare the linked Apache, Node.js, and Ruby security pages. Done means publishing a Cordova security page that explains how to report security bugs and links to relevant previous CVEs or announcements.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, jekyll
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100