Skip to content

Add SECURITY.md security policy documentation#214

Open
sahaj-13 wants to merge 2 commits into
mainfrom
sahaj-security-policy
Open

Add SECURITY.md security policy documentation#214
sahaj-13 wants to merge 2 commits into
mainfrom
sahaj-security-policy

Conversation

@sahaj-13
Copy link
Copy Markdown
Collaborator

@sahaj-13 sahaj-13 commented May 7, 2026

Summary

This PR adds a SECURITY.md file to document the security policy and responsible disclosure process for the AutoAudit project.

What changed

  • Added security reporting guidance
  • Documented security-sensitive areas of the platform
  • Added CI/CD security control notes
  • Included Bandit, CodeQL, dependency scanning, and pull request review practices
  • Added recommendations for authentication, rate limiting, file upload security, and future identity provider improvements

Value

This improves the project’s DevSecOps documentation by giving contributors a clear reference for reporting vulnerabilities and understanding key security controls.

Copy link
Copy Markdown
Collaborator

@du-dhartley du-dhartley left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This file, while well intentioned, reads like a security backlog. This is not the place to put what this repository should be working on, what issues should be fixed and what we need to do. Please pull all backlog related items out of this file.

The current state of this file, including branches that are not used and are not valid, gives malicious actors (this repository is public, remember) advice that we aren't protecting specific endpoints the way we should be.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants