astropy / astropy/astropy-project

How to handle security reports

Open
#359 2 comments 0 reactions 0 assignees View on GitHub
policy :page_facing_up:
Dominant language
TeX
Stars
48
Forks
48
PR merge metrics
No merged PRs in 30d

Description

There is a need to:

1. Have a formal chain of communication when a report comes in. Not everyone watch GitHub, etc. Who needs to know.
2. Update https://github.com/astropy/astropy/blob/main/SECURITY.md with any addition to the policy. Would be nice to tell people that they can open PR but be discrete about it or whatever.

p.s. I wonder if we can emulate some from https://www.python.org/dev/security/

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading SECURITY.md and the Python security policy linked in the issue. Define the project's formal communication chain for incoming reports and document the agreed reporting and pull-request guidance in SECURITY.md; done means the policy and notification responsibilities are explicit.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.