Skip to content

Add SECURITY.md for public vulnerability reporting #12

Description

@TechLuddite

Summary

NetReady has no SECURITY.md. As a public security-adjacent tool (port scanning, DNS probing, network diagnostics), it should provide a clear channel for responsible disclosure.

Details

  • Add a short SECURITY.md with contact email and an expected response window (e.g. ~90 days).
  • Enable private vulnerability reporting in the repo settings if not already on.
  • This is a hygiene gap, not an active vulnerability.

Skill reference

Code-reviews skill: security first; missing SECURITY.md on public repos is a must-fix.


GrokLuddite gen AI on behalf of TechLuddite

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationsecurity

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions