Skip to content

Conversation

@timea-solid
Copy link
Member

This should be a basis to start a security policy which can be than copied on all repositories we own.

Copy link
Contributor

@TallTed TallTed left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Language tweaks for clarity

@Otto-AA
Copy link

Otto-AA commented Apr 13, 2023

Looks good to me.

Depending on how you are able to deal with it I would consider to enable "private vulnerability reporting". If a security issue is public, everyone can read about them and abuse them until they are fixed. If they are private, they would have to find them out themself to abuse them, making it harder. I think in a project such as SolidOS this could be important, as I expect the time to a fix to be rather long (as it is largely volunteer-based).

I guess, then the main question would be if it is easy for you to define an appropriate group of people that can read these issues (eg people who regularly contribute to the project).

timea-solid and others added 5 commits April 14, 2023 09:12
Co-authored-by: Ted Thibodeau Jr <[email protected]>
Co-authored-by: Ted Thibodeau Jr <[email protected]>
Co-authored-by: Ted Thibodeau Jr <[email protected]>
Co-authored-by: Ted Thibodeau Jr <[email protected]>
Co-authored-by: Ted Thibodeau Jr <[email protected]>
@timea-solid
Copy link
Member Author

Thank you @TallTed for fixing it. Seeing the improvements one could totally see I wrote it late last night 😅

@Otto-AA you bring up really good points. I need to think about it and maybe bring it up in the meeting. I am happy we started the process :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: In review

Development

Successfully merging this pull request may close these issues.

4 participants