-
Notifications
You must be signed in to change notification settings - Fork 293
Closed
Description
Adding a Security Policy is important to provide guidance on how users can report potential vulnerabilities and communicate when vulnerabilities will be confirmed, fixed and disclosed to the public.
This is considered a good-practice and recommended by Github and Scorecard.
If you agree, I can open a PR to suggest a Security Policy! We can then work together to communicate how the repo can best handle vulnerability reports.
Additional Context
Hi! I'm Gabriela and I work on behalf of Google and the OpenSSF suggesting supply-chain security changes :)
Metadata
Metadata
Assignees
Labels
No labels