Repository navigation
docs: add SECURITY.md (vulnerability + safety disclosure policy) - #206
Merged
Merged
Conversation
Root security policy for the public repo. Covers private vulnerability reporting (via GitHub private advisories, now enabled) for ordinary code/dependency issues, plus the project-specific safety-disclosure scope: raw harmful content leaking into the repo/history, leaked secrets, or a pull path to the private degraded adapters. Ties to RESPONSIBLE_USE.md; asks reporters to describe the class of problem privately rather than post exploits/harmful content publicly. Closes #205
PR Reviewer Guide 🔍Here are some key observations to aid the review process:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
User description
What
Adds a root
SECURITY.mdfor the now-public repo.Covers two report types, both privately via GitHub private vulnerability reporting (enabled on the repo — Report a vulnerability):
Asks reporters to describe the class of problem privately rather than post exploits or harmful content publicly, and ties to
RESPONSIBLE_USE.md. Out-of-scope: the study's disclosed judge-proxy limitations, and the base model/public datasets' own behavior.Closes #205
PR Type
Documentation
Description
Add private vulnerability and safety-disclosure reporting policy.
Define supported branch and security reporting scope.
Establish disclosure safeguards and best-effort response expectations.
Link defensive guidance to
RESPONSIBLE_USE.md.File Walkthrough
SECURITY.md
Document private security reporting and responsible disclosureSECURITY.md
main, with defensiveframing and a link to
RESPONSIBLE_USE.md.to GitHub private reporting; specify report details and best-effort
acknowledgment expectations.
adapter exposure; exclude documented study limitations and upstream
model/dataset behavior.
unauthorized access or redistribution, and welcome good-faith research
with a conditional non-action commitment.