Create SECURITY.md - #14
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: dff694efcc
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| ## Reporting a Vulnerability | ||
|
|
||
| Use this section to tell people how to report a vulnerability. |
There was a problem hiding this comment.
Provide an actual vulnerability reporting channel
When a researcher discovers a vulnerability, this section provides only template instructions and no email address, private advisory link, or other reporting mechanism, so the newly advertised security policy gives them no way to disclose the issue privately. Replace the placeholder with a concrete reporting channel and response expectations.
Useful? React with 👍 / 👎.
| | 5.1.x | :white_check_mark: | | ||
| | 5.0.x | :x: | | ||
| | 4.0.x | :white_check_mark: | | ||
| | < 4.0 | :x: | |
There was a problem hiding this comment.
Align the support table with actual project versions
For anyone checking whether the current release is eligible for security fixes, this table is misleading: the project manifest identifies the application as version 0.1.0, while the policy lists unrelated 4.x and 5.x releases and classifies every version below 4.0 as unsupported. Document the versions or deployment policy that this repository actually uses instead of retaining the template values.
Useful? React with 👍 / 👎.
Security md