Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adopt a basic security policy #2040

Merged
merged 1 commit into from
Dec 16, 2024
Merged

Adopt a basic security policy #2040

merged 1 commit into from
Dec 16, 2024

Conversation

tim-schilling
Copy link
Member

This informs users to submit security reports through GitHub's private vulnerability mechanism.

Description

This formalizes a basic security policy for the project. I'm unsure about the supported version aspect. I think it's factual. If there's a bug in an older version that's not in the newer, we're not backporting it. However, we have done this in the past with a significant vulnerability.

Checklist:

  • I have added the relevant tests for this change.
  • I have added an item to the Pending section of docs/changes.rst.

Sorry, something went wrong.

Verified

This commit was signed with the committer’s verified signature.
renovate-bot Mend Renovate
This informs users to submit security reports through GitHub's private vulnerability mechanism.
@tim-schilling tim-schilling requested review from a team, matthiask and elineda and removed request for a team December 14, 2024 20:30
Copy link
Member

@matthiask matthiask left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Excellent, thank you!

Copy link
Member

@elineda elineda left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As we have no LTS we aren't bound to update older version. So it's ok to do only lastest..

ok for me. ty

@matthiask matthiask merged commit f3f6049 into main Dec 16, 2024
53 checks passed
@matthiask matthiask deleted the security-policy branch December 16, 2024 09:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants