Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add a security policy #178

Merged
merged 1 commit into from Apr 21, 2023
Merged

Add a security policy #178

merged 1 commit into from Apr 21, 2023

Conversation

pnacht
Copy link
Contributor

@pnacht pnacht commented Apr 14, 2023

Fixes #179.

As described in the issue, this PR adds a security policy to the project.

It currently offers two means of reporting: via an email (currently a placeholder) or using GitHub's private reporting feature (which must be enabled to work). It also suggests a 90-day remediation timeline, which is pretty standard.

If you'd rather change something (only offer one reporting method, add an actual email, use an external website instead, change the timeline, etc), let me know and I'll happily modify the PR.

Signed-off-by: Pedro Kaj Kjellerup Nacht <pnacht@google.com>
@thockin thockin merged commit c331f48 into go-logr:master Apr 21, 2023
14 checks passed
@pnacht
Copy link
Contributor Author

pnacht commented Apr 24, 2023

@thockin Thanks for merging this PR. However, it currently includes a "???@???" placeholder for the email. Let me know if you want me to send another PR to fix that. Just let me know which email to use or if you'd rather just use GitHub's private reporting feature.

@thockin
Copy link
Contributor

thockin commented Apr 24, 2023 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Add a security policy
3 participants