aurelia / aurelia/documentation

Please include a security policy statement

Open
#260 0 comments 1 reaction 0 assignees View on GitHub
documentation
Dominant language
No language data
Stars
104
Forks
108
PR merge metrics
No merged PRs in 30d

Description

**I'm submitting a feature request**
- **Library Version:**
1.0.0

**Current behavior:**

There is no statement in the documentation or on the Aurelia Website about the current security policy.

**Expected/desired behavior:**

I would expect there to be a statement that clearly explains how to notify the core team of security issues, and how the team will respond to security vulnerabilities.

For example, here is the Ember.js security policy:

http://emberjs.com/security/
- **What is the expected behavior?**

See above.
- **What is the motivation / use case for changing the behavior?**

It would provide a clear process for the team to follow in the event of security vulnerabilities in the framework (which will happen eventually), and increase the confidence of potential users, particularly those with security or compliance requirements.

Speaking personally, I really like what I see with Aurelia, but I can't recommend it to my company without clearly understanding what the process for security and bug fix updates will be.

Contributor guide

Open the contributing guide

Research direction

Review the repository documentation and the Aurelia Website security-policy locations mentioned in the issue, using the Ember.js policy as a reference. Confirm where the statement should live and what notification and vulnerability-response process the core team wants to publish. Done means the policy is clearly available to users in the relevant documentation or website location.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
28/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.