SECURITY.md in .github needs actionable reporting instructions

Open
#11 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
48/100
Issue type
Documentation
Clarity
Mostly clear
Activity status
Quiet
Tech stack
github

Research direction

Start with .github/SECURITY.md, the linked NeoNephos security guidelines, and GitHub's private vulnerability reporting documentation. Decide whether to inline reporting instructions or document private reporting, then ensure the file explains how to report, what to include, response timing, and disclosure expectations.

Written by the indexing model from the issue text.

Description

Problem

The current SECURITY.md in .github (after .github#10) only contains:

These guidelines follow the NeoNephos Security Guidelines.

As of now, the linked NeoNephos security guidelines do not provide actionable details for vulnerability reporters. A contributor who discovers a security issue has no immediate instructions on what to do.

What a useful SECURITY.md should provide

At minimum:

  • Clear "Do NOT open a public issue" warning
  • Reporting mechanism — email address, private vulnerability reporting link, or both
  • What information to include (repo, type of issue, reproduction steps, impact)
  • Expected response timeline (e.g., acknowledgement within X days)
  • Disclosure policy (coordinated disclosure window)

Current status

NeoNephos does not yet provide these details in their upstream security guidelines. Until they do, we should either:

  1. Inline the essential reporting instructions directly in our SECURITY.md, or
  2. Enable GitHub Private Vulnerability Reporting org-wide and document that as the mechanism

Related

Dominant language
No language data
Stars
0
Forks
0
Avg merge
10m
Merged PRs (30d)
2

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from openmcp-project/.github

All issues in openmcp-project/.github

Similar issues

More Documentation issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.