This repository will hold session tokens, talk to servers over the network, and
be linked into clients on other people's devices. It has no security policy and
no stated way to report a vulnerability privately, so the only route a finder has
today is a public issue.
Done when
SECURITY.md exists, names the supported versions, gives the private reporting
route, and states what a reporter can expect and by when. Private vulnerability
reporting is enabled on the repository. README.md links to it. Which route
that is, and whether it is the same address #107 publishes for a conduct
report, is entry 5 of #1.
This repository will hold session tokens, talk to servers over the network, and
be linked into clients on other people's devices. It has no security policy and
no stated way to report a vulnerability privately, so the only route a finder has
today is a public issue.
Done when
SECURITY.mdexists, names the supported versions, gives the private reportingroute, and states what a reporter can expect and by when. Private vulnerability
reporting is enabled on the repository.
README.mdlinks to it. Which routethat is, and whether it is the same address #107 publishes for a conduct
report, is entry 5 of #1.