Skip to content

Add SECURITY.md and a private vulnerability reporting channel #279

Description

@eaitbrahim

keel holds exchange API credentials and places live orders. Once strangers read the source, someone will eventually find a way to make it misbehave — and there is currently no private channel to report it. The only options are a public issue (which discloses it to everyone simultaneously) or nothing.

Acceptance

  • SECURITY.md at repo root
  • A private reporting route — GitHub private vulnerability reporting enabled, and/or a dedicated address
  • Stated response expectation (acknowledge within N days), honestly sized for a solo maintainer
  • Scope: what counts as a vulnerability here. Worth being explicit that a rail that can be bypassed is a security issue, not merely a bug — rails are the product
  • What is out of scope: strategy performance, market losses, a user's own key handling

Note

Enable GitHub's private vulnerability reporting in repo settings at the same time; the file alone gives no channel.

Metadata

Metadata

Assignees

Labels

open-sourceWork toward making keel genuinely open sourcerailsUn-overridable safety rail / guard (Compliance & rails)

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions