Skip to content

docs: rewrite vulnerability disclosure and remediation docs - #449

Open
jescalada wants to merge 7 commits into
finos:mainfrom
jescalada:improve-vulnerability-docs
Open

jescalada wants to merge 7 commits into
finos:mainfrom
jescalada:improve-vulnerability-docs

Conversation

@jescalada

Copy link
Copy Markdown
Contributor

This PR simplifies some of the existing wording, adds standards (such as a SECURITY.md template) and rewrites a few sections to reflect the new, native GitHub vulnerability disclosure process.

I've used GitProxy as an example here and there, because it already has battle-tested security and release tooling for other projects to benefit.

Feel free to edit the wording wherever appropriate, and fill in anything I might have missed!

@netlify

netlify Bot commented Sep 16, 2026

Copy link
Copy Markdown

Deploy Preview for eager-borg-83c1a5 ready!

Name Link
🔨 Latest commit 71a70ec
🔍 Latest deploy log https://app.netlify.com/projects/eager-borg-83c1a5/deploys/6aaa20c58256ec00082e8e6a
😎 Deploy Preview https://deploy-preview-449--eager-borg-83c1a5.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@jescalada jescalada changed the title docs: rewrite vulnerability-related docs docs: rewrite vulnerability disclosure and remediation docs Sep 16, 2026

@TheJuanAndOnly99 TheJuanAndOnly99 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @jescalada this is amazing, thank you! I made just 1 small suggested change.

![Security Policy](security-policy.png)

3. Follow the submission steps in the project's security policy. Usually, this means clicking the "Report a vulnerability" button and filling in the [requested details](#details-to-include).
4. If the project doesn't have a SECURITY.md policy available, submit the vulnerability via email to a project Maintainer (ideally, the Lead Maintainer). You can find contact emails in the project's `MAINTAINERS.md` file. Also, CC the email to [security@finos.org](mailto:security@finos.org).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
4. If the project doesn't have a SECURITY.md policy available, submit the vulnerability via email to a project Maintainer (ideally, the Lead Maintainer). You can find contact emails in the project's `MAINTAINERS.md` file. Also, CC the email to [security@finos.org](mailto:security@finos.org).
4. If the project doesn't have a SECURITY.md policy available and the "Report a vulnerability" button is not enabled, submit the vulnerability via email to a project Maintainer (ideally, the Lead Maintainer). You can find contact emails in the project's `MAINTAINERS.md` file. Also, CC the email to [security@finos.org](mailto:security@finos.org).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants