Skip to content

Define a security policy #1658

@jpmcb

Description

@jpmcb

cobra needs a security policy.

Generally, this should define:

  • How users should report vulnerabilities
  • How cobra maintainers respond
  • How known security vulnerabilities and CVEs are communicated to the community

Inspiration from Open Web Application Security Project

We'd also like any input from the community since, in the end, all these policies serve the community

Metadata

Metadata

Assignees

Labels

adminFor general admin tasks to be done usualy by maintainershelp-wantedAn issue that the maintainers would like help resolvingkind/securityRelated to projects/libraries that depend on cobralifecycle/frozenPrevents GitHub actions from labeling issues / PRs with stale and rotten

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions