Skip to content

docs: add SECURITY.md#321

Open
Mesut Oezdil (mesutoezdil) wants to merge 1 commit into
agent-substrate:mainfrom
mesutoezdil:docs/add-security-policy-v2
Open

docs: add SECURITY.md#321
Mesut Oezdil (mesutoezdil) wants to merge 1 commit into
agent-substrate:mainfrom
mesutoezdil:docs/add-security-policy-v2

Conversation

@mesutoezdil

@mesutoezdil Mesut Oezdil (mesutoezdil) commented Jun 26, 2026

Copy link
Copy Markdown
Contributor

Most open-source projects include a SECURITY.md so contributors and users know how to report vulnerabilities without opening a public issue.
This repo currently has no such file, which means reporters have no obvious path and may default to opening a public issue instead, which exposes the vulnerability before a fix is ready.

This PR adds a minimal SECURITY.md that covers:

  • A private reporting path (GitHub Advisory + ate-dev mailing list)
  • Severity-based response time targets, honest about the team size
  • Supported versions (none yet, main only)
  • Scope: what is and is not covered

Happy to adjust the response times, scope, or wording if this does not match how the maintainers want to handle security reports.

Comment thread SECURITY.md
**Do not open a public GitHub issue for security vulnerabilities.**

Use [GitHub Private Vulnerability Reporting](https://github.com/agent-substrate/substrate/security/advisories/new)
to report privately. Alternatively, email the maintainers at

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Uh, this is an open join mailinglist ...

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i can remove it and keep github private vuln reporting as the only path

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure how we want to handle these yet, but it seems premature while the repo is in pre-alpha state to issue vulns etc ...

@mesutoezdil

Copy link
Copy Markdown
Contributor Author

I'm not sure how we want to handle these yet, but it seems premature while the repo is in pre-alpha state to issue vulns etc ...

i can close this and reopen once the team has decided how to handle sec reports. alternatively, if you want a placeholder that just points to github advisory and omits the response time targets, i can simplify it to that. up2yu.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants