-
Notifications
You must be signed in to change notification settings - Fork 1
Create SECURITY.md for security policy #2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Create SECURITY.md for security policy #2
Conversation
Added a security policy outlining supported versions and vulnerability reporting.
|
@EthanCoderPenguin2012 is attempting to deploy a commit to the Ben's projects Team on Vercel. A member of the Team first needs to authorize it. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
This PR establishes a security policy for the project by adding a SECURITY.md file. The file provides a template structure for documenting supported versions and the process for reporting security vulnerabilities.
Key Changes
- Added SECURITY.md with a supported versions table showing which project versions receive security updates
- Included a reporting section for vulnerability disclosure procedures
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| Use this section to tell people about which versions of your project are | ||
| currently being supported with security updates. |
Copilot
AI
Dec 12, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The placeholder instructional text should be replaced with actual information about which versions are supported. This template content does not provide actionable information to users.
| Use this section to tell people how to report a vulnerability. | ||
|
|
||
| Tell them where to go, how often they can expect to get an update on a | ||
| reported vulnerability, what to expect if the vulnerability is accepted or | ||
| declined, etc. |
Copilot
AI
Dec 12, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The placeholder instructional text should be replaced with actual vulnerability reporting procedures, including contact information, expected response times, and the security disclosure process.
| Use this section to tell people how to report a vulnerability. | |
| Tell them where to go, how often they can expect to get an update on a | |
| reported vulnerability, what to expect if the vulnerability is accepted or | |
| declined, etc. | |
| To report a security vulnerability, please email our security team at [[email protected]](mailto:[email protected]). If you prefer, you may use our secure reporting form at [https://example.com/security-report](https://example.com/security-report). | |
| We aim to acknowledge your report within 3 business days and provide a more detailed response within 7 business days, including our assessment of the issue and an expected timeline for resolution. | |
| Once a vulnerability is confirmed, we will work with you to address the issue and keep you informed of our progress. After the vulnerability is resolved, we will notify you before public disclosure, unless you request otherwise. If the report is declined, we will provide a clear explanation. |
Added a security policy outlining supported versions and vulnerability reporting.