Skip to content

feat: add comprehensive security policy and responsible disclosure fr…#147

Merged
ogazboiz merged 1 commit intoLabsCrypt:mainfrom
Christopherdominic:feature/security-policy
Feb 22, 2026
Merged

feat: add comprehensive security policy and responsible disclosure fr…#147
ogazboiz merged 1 commit intoLabsCrypt:mainfrom
Christopherdominic:feature/security-policy

Conversation

@Christopherdominic
Copy link
Copy Markdown
Contributor

…amework

  • Add SECURITY.md with vulnerability reporting guidelines and response timelines
  • Update README.md and CONTRIBUTING.md with security policy references
  • Create GitHub issue template for security reports
  • Add automated security workflow with dependency scanning and CodeQL
  • Include verification script and setup checklist for maintainers
  • Implement responsible disclosure policy aligned with industry best practices

Closes #143

…amework

- Add SECURITY.md with vulnerability reporting guidelines and response timelines
- Update README.md and CONTRIBUTING.md with security policy references
- Create GitHub issue template for security reports
- Add automated security workflow with dependency scanning and CodeQL
- Include verification script and setup checklist for maintainers
- Implement responsible disclosure policy aligned with industry best practices

Closes LabsCrypt#143
@ogazboiz ogazboiz merged commit fb091fb into LabsCrypt:main Feb 22, 2026
Copy link
Copy Markdown
Contributor

@ogazboiz ogazboiz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Excellent addition! A SECURITY.md with clear response timelines (24h acknowledgement, 90-day disclosure), a private vulnerability reporting template, and an automated CodeQL + dependency scanning workflow is exactly what an open-source project needs at this stage. The setup checklist for admins is a thoughtful touch. ✅ Merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DX: Security Policy and Responsible Disclosure

2 participants