Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create a Security Policy #222

Merged
merged 3 commits into from Mar 20, 2023
Merged

Conversation

joycebrum
Copy link
Contributor

Changes

Closes #221

  • Create the security.md file with a standard body

It needs yet a security email to gather possible vulnerabilities reports.

I've proposed this vulnerability disclosure timeline but let me know if you are more confortable with a different one.

PS: the Security Advisory is a github tool to Vulnerabilities Disclosures (I've seen you've already familiar with it).

Besides that feel free to edit or suggest any changes to this document, it is supposed to reflect the amount of effort the team can offer to handle vulnerabilities.

SECURITY.md Outdated Show resolved Hide resolved
@joycebrum
Copy link
Contributor Author

Another option is to use the github advisories to receive vulnerabilities reports, if you rather I can update the doc to mention it instead of emailing. But it need to be enabled and it is in beta yet.

https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability

@alex alex merged commit c2fc3b1 into certifi:master Mar 20, 2023
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Create a Security Policy
2 participants