Skip to content

Remove fork-local SECURITY.md to inherit Mixpanel org security policy - #19

Open
scotmatson wants to merge 1 commit into
mixpanel-releasefrom
security/adopt-org-security-policy
Open

Remove fork-local SECURITY.md to inherit Mixpanel org security policy#19
scotmatson wants to merge 1 commit into
mixpanel-releasefrom
security/adopt-org-security-policy

Conversation

@scotmatson

@scotmatson scotmatson commented Aug 19, 2026

Copy link
Copy Markdown

What

Removes this repository's SECURITY.md.

Why

This fork currently ships the upstream rrweb community security policy, which routes vulnerability reports to rrweb's GitHub Security page and the rrweb-security@googlegroups.com community group — not to Mixpanel. On a public, Mixpanel-maintained fork, that means security reports can bypass Mixpanel's security team entirely.

What happens after this is merged

GitHub serves default community health files from an organization's .github repository to any repo that does not define its own. Mixpanel's org-wide policy lives here:

➡️ https://github.com/mixpanel/.github/blob/main/SECURITY.md

Because this repository will no longer have its own SECURITY.md, GitHub will automatically apply Mixpanel's org-wide SECURITY.md as this repo's policy. Vulnerability reports will then route to Mixpanel's disclosure channels (security@mixpanel.com / bug bounty) with proper scope guidance — no per-repo file required.

If a repository-specific policy is ever needed, adding a SECURITY.md back to this repo will override the org default (GitHub uses the repo's own file when present, and falls back to mixpanel/.github otherwise).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant