Skip to content

docs: add SECURITY.md (vulnerability + safety disclosure policy) - #206

Merged
kambleakash0 merged 1 commit into
mainfrom
security/add-security-md
Sep 9, 2026
Merged

kambleakash0 merged 1 commit into
mainfrom
security/add-security-md

Conversation

@kambleakash0

@kambleakash0 kambleakash0 commented Sep 9, 2026 •

Copy link
Copy Markdown
Owner

User description

What

Adds a root SECURITY.md for the now-public repo.

Covers two report types, both privately via GitHub private vulnerability reporting (enabled on the repo — Report a vulnerability):

  • ordinary code/dependency vulnerabilities (model gateway, eval harness, deps);
  • safety-posture issues specific to this project — raw harmful content that slipped into the repo/history, a leaked secret, or a pull path to the private degraded/DPO/attribution adapters.

Asks reporters to describe the class of problem privately rather than post exploits or harmful content publicly, and ties to RESPONSIBLE_USE.md. Out-of-scope: the study's disclosed judge-proxy limitations, and the base model/public datasets' own behavior.

Closes #205


PR Type

Documentation


Description

  • Add private vulnerability and safety-disclosure reporting policy.

  • Define supported branch and security reporting scope.

  • Establish disclosure safeguards and best-effort response expectations.

  • Link defensive guidance to RESPONSIBLE_USE.md.


File Walkthrough

Relevant files
Documentation
SECURITY.md
Document private security reporting and responsible disclosure

SECURITY.md

  • Add a root security policy covering current main, with defensive
    framing and a link to RESPONSIBLE_USE.md.
  • Direct software vulnerabilities and repository-specific safety issues
    to GitHub private reporting; specify report details and best-effort
    acknowledgment expectations.
  • Define in-scope harmful content, leaked credentials, and private
    adapter exposure; exclude documented study limitations and upstream
    model/dataset behavior.
  • Require coordinated disclosure, prohibit public exploits and
    unauthorized access or redistribution, and welcome good-faith research
    with a conditional non-action commitment.
+56/-0   

Root security policy for the public repo. Covers private vulnerability reporting
(via GitHub private advisories, now enabled) for ordinary code/dependency issues,
plus the project-specific safety-disclosure scope: raw harmful content leaking
into the repo/history, leaked secrets, or a pull path to the private degraded
adapters. Ties to RESPONSIBLE_USE.md; asks reporters to describe the class of
problem privately rather than post exploits/harmful content publicly.

Closes #205
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

🎫 Ticket compliance analysis 🔶

205 - Partially compliant

Compliant requirements:

  • Add a root SECURITY.md.
  • Direct ordinary code and dependency vulnerability reports to GitHub private vulnerability reporting rather than public issues.
  • Cover private reporting of raw harmful content, leaked secrets, and access paths to private adapters.
  • Tell reporters not to publish sensitive details or exploits in public issues.
  • Link to RESPONSIBLE_USE.md and preserve the project's defensive framing.

Non-compliant requirements:

None.

⏱️ Estimated effort to review: 1 🔵⚪⚪⚪⚪
🧪 No relevant tests
🔒 No security concerns identified
⚡ No major issues detected

@kambleakash0
kambleakash0 merged commit b6603d7 into main Sep 9, 2026
3 checks passed
@kambleakash0
kambleakash0 deleted the security/add-security-md branch September 9, 2026 08:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add SECURITY.md (vulnerability + safety disclosure policy)

1 participant