argoproj-labs / argoproj-labs/appsource

Add SECURITY.md

Open
#45 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
25
Forks
3
PR merge metrics
No merged PRs in 30d

Description

The Argo maintainers recently agreed to require all Argoproj Labs project repositories to contain a `SECURITY.md` file which documents:
* Contact information for reporting security vulnerabilities
* Some minimal information about policies, practices, with possibly links to further documentation with more details

This will help direct vulnerability reporting to the right parties which can fix the issue.

You are free to use the following as examples/templates:
* [Argoproj](https://github.com/argoproj/argoproj/blob/master/SECURITY.md)
* [Workflows](https://github.com/argoproj/argo-workflows/blob/master/SECURITY.md)
* [CD](https://github.com/argoproj/argo-cd/blob/master/SECURITY.md)

Also, please note that in the future we are exploring a requirement that argoproj-labs projects perform a [CII self-assessment](https://bestpractices.coreinfrastructure.org/en) to better inform its users about which security best practices are being followed.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the SECURITY.md examples linked in the issue, then create SECURITY.md in the repository root. Done means it documents vulnerability-reporting contact information and minimal security policies or practices, with links to further documentation where useful.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.