docs: add SECURITY.md with vulnerability reporting policy#14353
Open
sedat4ras wants to merge 1 commit intosphinx-doc:masterfrom
Open
docs: add SECURITY.md with vulnerability reporting policy#14353sedat4ras wants to merge 1 commit intosphinx-doc:masterfrom
sedat4ras wants to merge 1 commit intosphinx-doc:masterfrom
Conversation
Closes sphinx-doc#13063 Add a GitHub security policy file (.github/SECURITY.md) that documents how to report vulnerabilities in Sphinx. Covers: - GitHub Security Advisories as the preferred private channel - Email contact as an alternative - Supported versions policy - Disclosure process outline GitHub automatically surfaces this file in the Security tab and shows a "Report a vulnerability" button to users.
Author
|
Closing — CI failed on the job (unrelated to the change, but keeping the PR clean). Will reopen once the issue is investigated. |
Author
|
Note on the CI failure: the |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Adds
.github/SECURITY.mdto publish Sphinx's security vulnerability reporting policy.Closes #13063
GitHub automatically surfaces this file in the repository's Security tab and shows a "Report a vulnerability" button to users, replacing the generic GitHub message with project-specific guidance.
The policy documents:
admin@sphinx-doc.org— please update if this is incorrect)References