Skip to content

docs: add org-wide default security policy - #8

Draft
alukach wants to merge 1 commit into
mainfrom
docs/security-policy
Draft

alukach wants to merge 1 commit into
mainfrom
docs/security-policy

Conversation

@alukach

@alukach alukach commented Oct 1, 2026

Copy link
Copy Markdown
Member

Adds a default SECURITY.md. GitHub uses this for every Development Seed repo that doesn't have its own, linking it from each repo's Security tab and the new-issue page.

It directs reporters to GitHub's private vulnerability reporting instead of public issues and sets expectations for acknowledgement, advisories/CVEs, and supported versions.

Note: private vulnerability reporting is a per-repo setting (or can be enabled for all repos under org Settings → Code security). For repos where it's off, the policy tells reporters to request a private contact via an issue without disclosing details.

Related: developmentseed/stac-auth-proxy#218 (repo-specific policy).

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant