Skip to content

DOC: Add SECURITY.md and enable private vulnerability reporting #891

Description

@mmcky

Problem

The repository has no SECURITY.md and no documented private channel for reporting a vulnerability. For a package with thousands of forks, a JOSS publication, and wide use in teaching environments, a finder's only options today are a public issue (which discloses the problem before a fix exists) or an untracked email (no SLA, no audit trail).

GitHub Private Vulnerability Reporting is a one-click enablement in repository settings and gives reporters a private, tracked channel with a coordinated-disclosure workflow.

Acceptance criteria

  • SECURITY.md at the repository root: supported versions, how to report, expected response time
  • GitHub Private Vulnerability Reporting enabled
  • SECURITY.md points at the private reporting channel rather than an email address
  • Consistent with any QuantEcon org-level security policy; if one exists, reference it rather than restating it

From the July 2026 technical-debt audit (AI-assisted; claims verified against 28d4b3b on 2026-07-25).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions