Skip to content

docs: add root SECURITY.md for responsible vulnerability disclosure#487

Open
ayushsri-dev wants to merge 1 commit into
ProdigyV21:mainfrom
ayushsri-dev:docs/Security.md
Open

docs: add root SECURITY.md for responsible vulnerability disclosure#487
ayushsri-dev wants to merge 1 commit into
ProdigyV21:mainfrom
ayushsri-dev:docs/Security.md

Conversation

@ayushsri-dev

Copy link
Copy Markdown

Summary

This PR introduces a production-quality, root-level SECURITY.md file to establish clear vulnerability reporting guidance and document ARVIO's security policy. It also adds minimal references to the security policy in README.md and PRIVACY.md.

Proposed Changes

  • [NEW] SECURITY.md: Added a dedicated repository Security Policy covering:
    • Active development status on main and release support scope.
    • Strict prohibition of public disclosure through GitHub issues, Discord, or public forums.
    • Neutral private vulnerability reporting guidance while private channels are established.
    • Practical technical context to include in reports (specifying ARVIO components such as Android, Web UI, Netlify auth functions, Supabase Edge Functions, and integrations).
    • Explicit warning against including live production credentials, session keys, or API tokens in reports.
    • Coordinated disclosure expectations.
  • README.md: Updated Privacy section heading to Privacy And Security with a minimal link to SECURITY.md.
  • PRIVACY.md: Added a minimal reference to SECURITY.md in the Contact section for security-sensitive inquiries.

Maintainer Follow-up

Maintainer follow-up: No verified private vulnerability-reporting mechanism is currently exposed by the repository. The policy therefore avoids assuming that GitHub Private Vulnerability Reporting is enabled or inventing a security contact. Maintainers can update the reporting section after enabling Private Vulnerability Reporting or designating an official private security contact.

Verification

  • Verified Markdown structure, link resolution, and formatting.
  • Verified that all listed components match existing repository architecture.
  • Ensured no fabricated email addresses, response SLAs, remediation deadlines, or unsupported security guarantees were introduced.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant