Skip to content

Add SECURITY.md with DDS deployment guidance#34

Open
zack-dev-cm wants to merge 1 commit into
unitreerobotics:mainfrom
zack-dev-cm:patch-1
Open

Add SECURITY.md with DDS deployment guidance#34
zack-dev-cm wants to merge 1 commit into
unitreerobotics:mainfrom
zack-dev-cm:patch-1

Conversation

@zack-dev-cm
Copy link
Copy Markdown

Summary

Adds a SECURITY.md for unitree_sdk2. The repository currently has no security policy, and GitHub issues are disabled for this repo, so this PR is using the available "Suggest a policy" contribution path.

The policy documents responsible reporting expectations, the DDS/RTPS trust boundary, safe command-control deployment guidance, example-use cautions, and dependency/binary provenance expectations.

Context

unitree_sdk2 exposes DDS publish/subscribe and RPC-style APIs that can be used for robot motion, arm, audio, video, configuration, and low-level motor command paths. Deployments should make the trusted-network and DDS Security assumptions explicit so downstream users do not treat examples or CRC checks as production security controls.

Notes

This PR intentionally avoids exploit instructions or packet-level details. It is meant to establish a public security policy and safer deployment baseline.

Expanded the security policy to include detailed reporting guidelines, trust boundaries, safety guidance, and dependency provenance.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant