SECURITY.md in .github needs actionable reporting instructions
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 48/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- github
- Domain
- documentation, security
Research direction
Start with .github/SECURITY.md, the linked NeoNephos security guidelines, and GitHub's private vulnerability reporting documentation. Decide whether to inline reporting instructions or document private reporting, then ensure the file explains how to report, what to include, response timing, and disclosure expectations.
Written by the indexing model from the issue text.
Description
Problem
The current SECURITY.md in .github (after .github#10) only contains:
These guidelines follow the NeoNephos Security Guidelines.
As of now, the linked NeoNephos security guidelines do not provide actionable details for vulnerability reporters. A contributor who discovers a security issue has no immediate instructions on what to do.
What a useful SECURITY.md should provide
At minimum:
- Clear "Do NOT open a public issue" warning
- Reporting mechanism — email address, private vulnerability reporting link, or both
- What information to include (repo, type of issue, reproduction steps, impact)
- Expected response timeline (e.g., acknowledgement within X days)
- Disclosure policy (coordinated disclosure window)
Current status
NeoNephos does not yet provide these details in their upstream security guidelines. Until they do, we should either:
- Inline the essential reporting instructions directly in our SECURITY.md, or
- Enable GitHub Private Vulnerability Reporting org-wide and document that as the mechanism
Related
- Dominant language
- No language data
- Stars
- 0
- Forks
- 0
- Avg merge
- 10m
- Merged PRs (30d)
- 2
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from openmcp-project/.github
-
Dependency Dashboard Open
Difficulty 5/5 Over a week Newbie friendliness 15/100
openmcp-project/.github#16 ·
All issues in openmcp-project/.github
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
bancolombia/sentinel#22 ·
-
test md OpenCI
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
optimization optimization:agents-md-curator
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
githubnext/gh-aw-cao#13143 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 94/100
objectionary/hone-maven-plugin#1061 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
redhat-developer/rhdh-plugins#4887 · 2 comments ·