Skip to content

Tell a security researcher where to report - #52

Merged
ww-mw merged 1 commit into
mainfrom
add-security-policy
Oct 1, 2026
Merged

ww-mw merged 1 commit into
mainfrom
add-security-policy

Conversation

@ww-mw

@ww-mw ww-mw commented Oct 1, 2026

Copy link
Copy Markdown
Member

Adds SECURITY.md, copied verbatim from the consuming data-explorer-vscode
repo, which has carried it since its first content commit.

This repo is public and separately reportable, but had no policy file, so
GitHub offered no "Report a vulnerability" path here and a researcher landing
on it had to guess an address. The reporting channel is MathWorks'
(security@mathworks.com + the Vulnerability Disclosure Policy), not this
repo's, so the file is a byte-identical copy rather than a second wording that
could drift from it.

Docs only — no source, build, or test changes.

🤖 Generated with Claude Code

The vscode repo that consumes this one has carried a SECURITY.md since its
first content commit; this repo, public and separately reportable, had none,
so GitHub offered no "Report a vulnerability" path and a researcher landing
here had to guess an address. Copy the policy verbatim rather than word a
second one: the reporting channel is MathWorks', not this repo's, and two
texts that drift would be worse than one.
@ww-mw
ww-mw merged commit 48cd0a4 into main Oct 1, 2026
4 checks passed
@ww-mw
ww-mw deleted the add-security-policy branch October 1, 2026 13:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant