Skip to content

docs: add security policy and disclosure process - #14

Closed
routeplane-ops wants to merge 4 commits into
mainfrom
docs/security-policy
Closed

docs: add security policy and disclosure process#14
routeplane-ops wants to merge 4 commits into
mainfrom
docs/security-policy

Conversation

@routeplane-ops

Copy link
Copy Markdown
Collaborator

Adds the public vulnerability disclosure policy and coordinated reporting process.

This repo had no SECURITY.md, so a researcher who found something had no
documented way to report it privately and no idea what response to expect. For a
security product that is a real gap, not a paperwork one.

Mirrors the process already published in routeplane-ce (72-hour acknowledgement,
7-day assessment, 90-day coordinated disclosure, no paid bounty and we say so),
with the scope written for what THIS repo actually ships rather than copied.
@routeplane-ops

Copy link
Copy Markdown
Collaborator Author

Changes are already present on main.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants