Skip to content

docs: add security reporting guidance#147

Open
willchen96 wants to merge 1 commit into
mainfrom
add-security-reporting-guidance
Open

docs: add security reporting guidance#147
willchen96 wants to merge 1 commit into
mainfrom
add-security-reporting-guidance

Conversation

@willchen96
Copy link
Copy Markdown
Owner

Summary

Add security reporting guidance to the contributing guide.

Changes

  • Added a Security section to CONTRIBUTING.md.
  • Directs security vulnerability reports to GitHub private vulnerability reporting instead of public issues.
  • Notes that maintainers will aim to respond promptly and coordinate disclosure.

Why

Security reports should avoid public disclosure until they can be reviewed and remediated responsibly.

Testing

  • Not run; docs-only change.

amal66 added a commit to amal66/mike that referenced this pull request May 25, 2026
Chapter: 02 - Open-source collaboration.

Plain-English map:
Add a code of conduct, security policy, issue templates, and a pull request
template. These files tell people how to report bugs, propose changes, and
disclose vulnerabilities without guessing.

Why it matters:
Open-source projects are not only code. They need a shared operating manual
so first-time contributors know the rules of the room and maintainers get the
information they need.

Principle:
Healthy collaboration is documented. A project should make the safe path the
obvious path, especially for security reports.

Precedent borrowed:
GitHub community-health conventions and the security-reporting guidance
requested in upstream PR willchen96#147.

Upstream base: willchen96/mike@d39f580.
Original local commit: 045bdb7.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant