Skip to content

docs: add SECURITY.md with vulnerability disclosure policy - #322

Open
Dev9269 wants to merge 626 commits into
lissy93:masterfrom
Dev9269:feat/add-security-md
Open

docs: add SECURITY.md with vulnerability disclosure policy#322
Dev9269 wants to merge 626 commits into
lissy93:masterfrom
Dev9269:feat/add-security-md

Conversation

@Dev9269

@Dev9269 Dev9269 commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

The repository currently shows 'Suggest a security policy' on the Security tab. This PR adds a SECURITY.md with:

  • Supported version table
  • Private vulnerability reporting instructions (GitHub + email)
  • Disclosure timeline policy
  • Reference to the previous CVE-2025-32778 advisory
  • Security-relevant configuration notes for future reporters

Fixes the missing security policy on the repo.

bolens and others added 30 commits April 17, 2024 09:08
style: consistency between additional resources descriptions
lissy93 and others added 26 commits May 18, 2026 18:32
…g-display

fix: show OCSP stapling as informational, not pass/fail
Prevent IPv6 DNS records from being visually truncated
Signed-off-by: Erwan HervΓ© <erwan.herve@outlook.fr>
Signed-off-by: Erwan HervΓ© <erwan.herve@outlook.fr>
chore: add OCI standard labels to Dockerfile
…ncation

fix: wrap IPv6 addresses in DNS records card to prevent visual truncation
Fix typos, grammar, and broken links in README
Co-authored-by: Alicia Sykes <lissy93@users.noreply.github.com>
@Dev9269

Dev9269 commented Jul 23, 2026

Copy link
Copy Markdown
Contributor Author

@lissy93 This adds a SECURITY.md to replace the 'Suggest a security policy' prompt on the Security tab. Includes disclosure instructions, supported versions, and references CVE-2025-32778. Ready for review whenever you have a moment.

@netlify

netlify Bot commented Jul 23, 2026

Copy link
Copy Markdown

βœ… Deploy Preview for web-check ready!

Built without sensitive environment variables

Name Link
πŸ”¨ Latest commit e1472c5
πŸ” Latest deploy log https://app.netlify.com/projects/web-check/deploys/6a67c2bdfa89610009e5d358
😎 Deploy Preview https://deploy-preview-322--web-check.netlify.app
πŸ“± Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
πŸ€– Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@lissy93

lissy93 commented Jul 23, 2026

Copy link
Copy Markdown
Owner

Thanks @Dev9269!

Good spot that security.md is missing, I should definitely create that.
I need to come back and spend a bit of time updating web-check in general

I usually don't list things which need to be kept updated in the security policy. Since the known CVEs can already be seen in the security tab, and for the version support if the version is linier then it's often just easier to say current major + minor is supported.

Usually it's easier if maintainer writes security.md, as the content will differ from repo to repo.

I'll take a proper look at the PR soon :)

@Dev9269
Dev9269 force-pushed the feat/add-security-md branch from ddb67ca to e1472c5 Compare July 27, 2026 20:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.