Skip to content

docs: add SECURITY.md with vulnerability reporting policy#383

Open
RehanAhmad25 wants to merge 1 commit into
imDarshanGK:mainfrom
RehanAhmad25:add/security
Open

docs: add SECURITY.md with vulnerability reporting policy#383
RehanAhmad25 wants to merge 1 commit into
imDarshanGK:mainfrom
RehanAhmad25:add/security

Conversation

@RehanAhmad25

Copy link
Copy Markdown

Description

This PR adds a SECURITY.md file to the repository root. LocalMind currently has no defined security policy, leaving contributors and users with no safe, private channel to report vulnerabilities. This change establishes a responsible disclosure process following GitHub's recommended best practices.

Closes #375

Type of Change

  • 📝 Documentation update
  • 🔒 Security

Changes Made

  • Added SECURITY.md at the root of the repository
  • Added explicit contact details with maintainer profile link
  • Included expected response timeline for reported vulnerabilities
  • Outlined responsible disclosure policy with 30-day embargo period
  • Added OWASP external reference link

How Has This Been Tested?

Documentation only change : no code was modified, no functional testing required.

  • Verified SECURITY.md renders correctly on GitHub
  • Confirmed GitHub Security tab now detects and displays the policy

Checklist

  • My code follows the existing code style of the project
  • I have performed a self-review of my own code
  • My changes do not introduce any new warnings or errors
  • I have linked the related issue

@vercel

vercel Bot commented Jun 11, 2026

Copy link
Copy Markdown

@RehanAhmad25 is attempting to deploy a commit to the Darshan's projects Team on Vercel.

A member of the Team first needs to authorize it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security]: Add SECURITY.md to define vulnerability reporting process

1 participant