Skip to content

Suggestion to Implement Security Policy (SECURITY.md) for Enhanced Security #58

Description

@huawei-od-man

I hope you're doing well.

I would like to suggest enhancing the security of our project by defining a comprehensive security policy. Specifically, I recommend creating a SECURITY.md file in the root directory of the repository. This policy should include guidelines for vulnerability reporting and vulnerability publication.

You can easily create this file via the Security page, which provides a template. Just add some key information, such as an email address or a link for submitting vulnerabilities, to the SECURITY.md file and commit it.

For more detailed information on these security checks, you can refer to the OpenSSF Scorecard documentation.

I believe that addressing these security improvements will significantly strengthen our project's security posture. What are your thoughts on implementing these changes?

Thank you for considering this suggestion.

Best regards,
Cong Feng

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions