astropy / astropy/astropy-project
How to handle security reports
- Dominant language
- TeX
- Stars
- 48
- Forks
- 48
- PR merge metrics
- No merged PRs in 30d
Description
There is a need to:
1. Have a formal chain of communication when a report comes in. Not everyone watch GitHub, etc. Who needs to know.
2. Update https://github.com/astropy/astropy/blob/main/SECURITY.md with any addition to the policy. Would be nice to tell people that they can open PR but be discrete about it or whatever.
p.s. I wonder if we can emulate some from https://www.python.org/dev/security/
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reading SECURITY.md and the Python security policy linked in the issue. Define the project's formal communication chain for incoming reports and document the agreed reporting and pull-request guidance in SECURITY.md; done means the policy and notification responsibilities are explicit.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100