-
Notifications
You must be signed in to change notification settings - Fork 167
Create SECURITY.md #35
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Reviewer's GuideAdds a new SECURITY.md file establishing the project's security policy, vulnerability reporting procedures, best practices, and licensing terms for security contributions. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hey @Danielpeter-99 - I've reviewed your changes - here's some feedback:
- Consider adding an expected response and fix timeline (e.g. 72 hours acknowledgement, 30 days to remediation) to set clear expectations for reporters.
- You may want to include a PGP/GPG public key or other encryption method so that vulnerability reports can be submitted securely.
- It could be helpful to define severity levels or CVSS scoring to clarify how reports will be prioritized and handled.
Here's what I looked at during the review
- 🟡 General issues: 2 issues found
- 🟢 Security: all looks good
- 🟢 Testing: all looks good
- 🟢 Documentation: all looks good
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
| We aim to support the latest stable release of Evo AI and apply security updates as soon as possible. Please use the most recent version for the best security. | ||
|
|
||
| --- |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
suggestion: Consider adding guidance on how users can find the latest version or updates.
You might reference GitHub Releases or a security announcements channel to direct users to update information.
| We aim to support the latest stable release of Evo AI and apply security updates as soon as possible. Please use the most recent version for the best security. | |
| --- | |
| We aim to support the latest stable release of Evo AI and apply security updates as soon as possible. Please use the most recent version for the best security. | |
| To find the latest version and release notes, visit our [GitHub Releases page](https://github.com/your-org/evo-ai/releases). For important security announcements, please watch the repository or subscribe to our security advisories. | |
| --- |
| - Include as much detail as possible, including: | ||
| - Steps to reproduce the issue | ||
| - Potential impact | ||
| - Your suggestions (if any) for remediation |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🚨 suggestion (security): Consider adding 'Affected version(s)' to the list of details for vulnerability reports.
Requesting affected version(s) helps with triage and reproduction of security issues, leading to higher quality reports.
| - Include as much detail as possible, including: | |
| - Steps to reproduce the issue | |
| - Potential impact | |
| - Your suggestions (if any) for remediation | |
| - Include as much detail as possible, including: | |
| - Affected version(s) | |
| - Steps to reproduce the issue | |
| - Potential impact | |
| - Your suggestions (if any) for remediation |
| ## Responsible Disclosure | ||
|
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
suggestion: Consider defining or giving an example of 'reasonable time' for disclosure.
Specifying a typical timeframe (e.g., 'usually 90 days, adjustable based on circumstances') would clarify expectations for reporters.
| ## Responsible Disclosure | |
| ## Responsible Disclosure | |
| Please give us a reasonable time to investigate and address any reported security issues before any public disclosure. A reasonable time is typically **90 days** from the initial report, but may be adjusted based on the complexity or severity of the issue. We will keep you informed of our progress and coordinate disclosure timelines as needed. | |
Summary by Sourcery
Documentation: