bobluppes / bobluppes/graaf

Add a SECURITY.md with a vulnerability disclosure policy

Aperta Adatta ai principianti
#321 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
C++
Stelle
413
Fork
67
Merge medio
7h 24m
PR unite (30g)
53

Descrizione

## Summary

The repository has no `SECURITY.md` and no documented process for reporting a vulnerability.

## Current state

The repo root contains `CODE_OF_CONDUCT.md` and `CONTRIBUTING.md`, but no `SECURITY.md`. GitHub's "Security" tab has no security policy configured, and there's no mention anywhere (README, CONTRIBUTING, wiki) of how a vulnerability should be reported, what response time to expect, or which versions receive fixes.

## Why this matters

Teams evaluating a dependency for use in a production environment routinely check for a published vulnerability-disclosure process as part of their due-diligence/vendor-review checklist. Without a `SECURITY.md`, there's no clear, private channel to report a potential issue (e.g. a memory-safety bug reachable from untrusted input in the DOT parser, or an algorithmic complexity issue that could be abused as a DoS vector) — reporters are left to use public issues, which is inappropriate for anything sensitive before a fix is available.

## Suggested resolution

- Add a `SECURITY.md` describing:
- Which versions/branches currently receive security fixes.
- A private reporting channel (e.g. GitHub's "Private vulnerability reporting" feature, or a maintainer email).
- Expected acknowledgement/response timelines.
- Enable GitHub's private vulnerability reporting for the repository.
- Link `SECURITY.md` from the README.

## Acceptance criteria

- [ ] `SECURITY.md` exists at the repo root and is picked up by GitHub's Security tab.
- [ ] A private reporting mechanism is enabled and documented.
- [ ] README links to the security policy.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Look at the existing CODE_OF_CONDUCT.md and CONTRIBUTING.md files in the repository root for formatting. Use GitHub's documentation on creating a SECURITY.md file and enabling private vulnerability reporting. The new file should be placed in the repo root and linked from the README. Check the repository's Security tab after creation to confirm it is recognized.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Ambito
documentation, security
Tipo di issue
Documentazione
Difficoltà
1/5
Tempo stimato
Meno di un'ora
Stato di attività
Attiva
Chiarezza
Specificata chiaramente
Idoneità per principianti
85/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.