Skip to content

Fix/add security policy#4707

Closed
Youngyz1 wants to merge 3 commits into
OpenFn:mainfrom
Youngyz1:fix/add-security-policy
Closed

Fix/add security policy#4707
Youngyz1 wants to merge 3 commits into
OpenFn:mainfrom
Youngyz1:fix/add-security-policy

Conversation

@Youngyz1
Copy link
Copy Markdown

@Youngyz1 Youngyz1 commented May 6, 2026

Description

This PR [adds/changes/fixes]... (A description of your work goes here.)

Closes #__

Validation steps

  1. (How can a reviewer validate your work?)

Additional notes for the reviewer

  1. (Is there anything else the reviewer should know or look out for?)

AI Usage

Please disclose whether you've used AI anywhere in this PR (it's cool, we just
want to know!):

  • I have used Claude Code
  • I have used another model
  • I have not used AI

You can read more details in our
Responsible AI Policy

Pre-submission checklist

  • I have performed an AI review of my code (we recommend using /review
    with Claude Code)
  • I have implemented and tested all related authorization policies.
    (e.g., :owner, :admin, :editor, :viewer)
  • I have updated the changelog.
  • I have ticked a box in "AI usage" in this PR

Youngyz1 added 3 commits May 6, 2026 01:41
Added a security policy document outlining vulnerability reporting, supported versions, and best practices for self-hosted deployments.
Add SECURITY.md for vulnerability reporting and best practices
Updated comments for generating worker keys.
@github-project-automation github-project-automation Bot moved this to New Issues in Core May 6, 2026
@josephjclark
Copy link
Copy Markdown
Collaborator

Thank you for flagging this @Youngyz1 . I've gone ahead and fixed this myself on the main branch.

A security policy isn't just a document we add to a repo It has to be part of our organisational process. We already have several layers of security which apply to this repo, including AI audits and notes in the readme

When raising PRs, please try and keep them as small and focused as possible so that its easy for maintainers to merge them 🙏

@github-project-automation github-project-automation Bot moved this from New Issues to Done in Core May 12, 2026
@Youngyz1
Copy link
Copy Markdown
Author

Youngyz1 commented May 15, 2026 via email

@josephjclark
Copy link
Copy Markdown
Collaborator

Hi @Youngyz1

Thanks for reaching out. I'd love to help but I'm not sure really - we're not in a position to take on contributors right now. Even volunteer work comes with a big cost for the organisation, and you can see from the PR page that we're struggling to keep up with contributions as it is.

I'll take a look over the backlog and see if there's are some issues that would be suitable for you to volunteer on

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants