Skip to content

Latest commit

 

History

History
76 lines (52 loc) · 2.71 KB

File metadata and controls

76 lines (52 loc) · 2.71 KB

Security Team

This document outlines the security team structure and responsibilities for the Throttle project.

Security Team Members

Core Security Team

Role Name GitHub Email Responsibilities
Security Lead Sambhrant Maurya @sdeonvacation maurya.sam@hotmail.com Overall security strategy, vulnerability coordination, security policy
Developer [Contributors welcome] - - Code security reviews, security testing

Responsibilities

The security team is responsible for:

  1. Vulnerability Management

    • Monitoring and responding to security reports
    • Coordinating disclosure and patches for security vulnerabilities
    • Maintaining the security advisory process
  2. Security Reviews

    • Reviewing pull requests for security implications
    • Conducting periodic security audits of the codebase
    • Ensuring security best practices are followed
  3. Security Tooling

    • Maintaining security scanning tools (CodeQL, FindSecBugs, OWASP Dependency Check)
    • Reviewing and acting on security scan results
    • Keeping security tools and configurations up to date
  4. Security Documentation

    • Maintaining SECURITY.md policy
    • Documenting security architecture and threat models
    • Providing security guidance for contributors
  5. Incident Response

    • Responding to security incidents
    • Coordinating with stakeholders during security events
    • Post-incident analysis and improvements

Joining the Security Team

Contributors interested in joining the security team should:

  1. Have a proven track record of contributions to the project
  2. Demonstrate knowledge of security best practices
  3. Contact the Security Lead via email or GitHub

Security Team Meetings

  • Frequency: As needed, minimum quarterly
  • Format: Virtual meetings via GitHub Discussions or email
  • Topics: Vulnerability reviews, security roadmap, tool updates

Contact

For security-related questions or to report vulnerabilities, see SECURITY.md.

For security team coordination and non-urgent security matters, contact:

  • Primary: maurya.sam@hotmail.com
  • GitHub Issues: Use the security label for public security discussions (non-vulnerabilities only)

Security Team Charter

The security team operates under the following principles:

  1. Transparency: Security processes and decisions are documented and open
  2. Responsiveness: Security reports receive timely acknowledgment and resolution
  3. Continuous Improvement: Regular review and enhancement of security practices
  4. Community Collaboration: Working with the broader security community

Last updated: 2026-03-18