swagger-api / swagger-api/swagger-petstore
Add a security policy
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 334
- Forks
- 434
- PR merge metrics
- No merged PRs in 30d
Description
Hey there!
I belong to an open source security research community, and a member (@shellinjector) has found an issue, but doesn’t know the best way to disclose it.
If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.
Thank you for your consideration, and I look forward to hearing from you!
(cc @huntr-helper)
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the GitHub security policy guidance linked in the issue and confirm which email or other contact method maintainers want to publish. Add SECURITY.md with the approved disclosure instructions; done means security researchers have a clear responsible-disclosure contact path.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 1/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100