Skip to content

ENH: create a SECURITY.md file #131

@aburrell

Description

@aburrell

Requested feature

A new file that outlines how to report a security issue.

The problem or gap this feature will address

GitHub standards requests a security processes file.

The desired solution

# Security Policy

## Supported Versions

Use this section to tell people about which versions of your project are
currently being supported with security updates.

| Version | Supported          |
| ------- | ------------------ |
| 5.1.x   | :white_check_mark: |
| 5.0.x   | :x:                |
| 4.0.x   | :white_check_mark: |
| < 4.0   | :x:                |

## Reporting a Vulnerability

Use this section to tell people how to report a vulnerability.

Tell them where to go, how often they can expect to get an update on a
reported vulnerability, what to expect if the vulnerability is accepted or
declined, etc.

Possible alternatives

This could just be considered a bug or a normal issue.

Additional context

This would improve our community project health score.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions