argoproj-labs / argoproj-labs/appsource
Add SECURITY.md
- Dominant language
- Go
- Stars
- 25
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
The Argo maintainers recently agreed to require all Argoproj Labs project repositories to contain a `SECURITY.md` file which documents:
* Contact information for reporting security vulnerabilities
* Some minimal information about policies, practices, with possibly links to further documentation with more details
This will help direct vulnerability reporting to the right parties which can fix the issue.
You are free to use the following as examples/templates:
* [Argoproj](https://github.com/argoproj/argoproj/blob/master/SECURITY.md)
* [Workflows](https://github.com/argoproj/argo-workflows/blob/master/SECURITY.md)
* [CD](https://github.com/argoproj/argo-cd/blob/master/SECURITY.md)
Also, please note that in the future we are exploring a requirement that argoproj-labs projects perform a [CII self-assessment](https://bestpractices.coreinfrastructure.org/en) to better inform its users about which security best practices are being followed.
Contributor guide
Research direction
Start by reviewing the SECURITY.md examples linked in the issue, then create SECURITY.md in the repository root. Done means it documents vulnerability-reporting contact information and minimal security policies or practices, with links to further documentation where useful.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100