Skip to content

add SECURITY.md for CRA compliant private reporting - #126

Open
1Shubham7 wants to merge 1 commit into
masterfrom
feature/security-policy
Open

1Shubham7 wants to merge 1 commit into
masterfrom
feature/security-policy

Conversation

@1Shubham7

Copy link
Copy Markdown

closes - #124

Add a security policy so vulnerabilities in LinuxAid can be reported
privately, and to document supported versions, scope and disclosure.
Mirrors the policy KubeAid already has.

Claude-Session: https://claude.ai/code/session_01HfnMq8hzd5RWdULqTgCd6H

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The reviewed security policy changes have no unresolved blocking issues.

Review effort: Lite
Findings: None

What changed in this PR

Adds SECURITY.md with private vulnerability reporting guidance and CRA-compliant security policy details.

Changes:

  • Documents GitHub Advisory and email reporting channels.
  • Defines supported versions, scope, and disclosure practices.
  • Clarifies third-party module handling and reporter credit.
File Description
SECURITY.md Adds the repository security policy and reporting guidance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants