dankogai / dankogai/p5-encode

Please add a security policy

Open
#185 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Perl
Stars
37
Forks
54
PR merge metrics
No merged PRs in 30d

Description

Please add a SECURITY or SECURITY.md file to the distribution and root directory of the git repo that explains how to report a security vulnerability.

CPANSec has a guide for adding a security policy [1] and also links to software to generate security policies when you rebuild a distribution for release.

You can enable private vulnerability reporting in your GitHub repository [2]. This allows people to create private issues for security vulnerabilities, and lets your collaborators work on private forks. (GitHub also treats security policies as "first class" files along with the README and LICENSE files.)

[1] https://security.metacpan.org/docs/guides/security-policy-for-authors.html

[2] https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository

Note: this issue is part of a project by CPANSec to encourage popular CPAN distributions to add a security policy.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Read the CPANSec security-policy guide and the repository's distribution setup first. Add a SECURITY or SECURITY.md file at the repository root and ensure it is included in the distribution; done means it clearly explains how to report a security vulnerability.

Written by the indexing model from the issue text.

Assessment

Tech stack
perl
Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.