Git Product home page Git Product logo

Comments (12)

vdeturckheim avatar vdeturckheim commented on July 16, 2024

Great idea @mcollina .

Also we could imagine a "report a vulnerability" button to add to README, wdyt?

from security-wg.

mcollina avatar mcollina commented on July 16, 2024

👍 for that.

We should encourage this.

from security-wg.

reedloden avatar reedloden commented on July 16, 2024

I would recommend having a separate SECURITY.md in the top-level of a project providing all the necessary information on how to report an issue. See https://github.com/electron/electron/blob/master/SECURITY.md as an example.

from security-wg.

lirantal avatar lirantal commented on July 16, 2024

great stuff, had actually pondered exactly that a couple months back (https://twitter.com/liran_tal/status/933322223783424000), and recently me and @grnd shared some ideas related to this too

would love to push this forward, and we could gather a few checklist items to take a stub at. makes sense for me to push for SECURITY.md that projects can use (reminds me of https://github.com/securitytxt/security-txt)

from security-wg.

mhdawson avatar mhdawson commented on July 16, 2024

@lirantal sounds good.

from security-wg.

cjihrig avatar cjihrig commented on July 16, 2024

@vdeturckheim can the security-wg-agenda label be dropped?

from security-wg.

vdeturckheim avatar vdeturckheim commented on July 16, 2024

Dropping from agenda as I believe this should get into a broader evangelism strategy.

from security-wg.

lirantal avatar lirantal commented on July 16, 2024

What else would we want to do here?
We already have the following:

  1. Copy&Paste Example of a badge for READMEs
  2. Template that can be used for SECURITY.txt

Maybe we can add an evangelism section in this repo's README to better communicate (1) and (2) ?

from security-wg.

lirantal avatar lirantal commented on July 16, 2024

Closing for now that we have the badge and the policy file.

from security-wg.

mcollina avatar mcollina commented on July 16, 2024

I think this needs to documented and linked in the README of this wg. Otherwise the info is hard to find. Also, a blog post on the foundation medium would be awesome as well.

from security-wg.

lirantal avatar lirantal commented on July 16, 2024

@mcollina so besides the badge to also have a short section about it?

will try to work out a small post about our initiatives to send over but if someone else beats me to it go for it.

from security-wg.

mcollina avatar mcollina commented on July 16, 2024

I mean in this repo. The README does not link or provide info to this.

from security-wg.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.