Skip to content

Add security policy#52

Closed
alistair3149 wants to merge 1 commit into
masterfrom
worktree-add-security-policy
Closed

Add security policy#52
alistair3149 wants to merge 1 commit into
masterfrom
worktree-add-security-policy

Conversation

@alistair3149
Copy link
Copy Markdown
Member

@alistair3149 alistair3149 commented Jun 2, 2026

Adds a SECURITY.md so that vulnerabilities can be reported privately instead of through public issues or pull requests.

What

  • Documents supported versions (fixes ship in the latest major release, no backports).
  • Directs reporters to GitHub's private vulnerability reporting rather than public channels.
  • Describes the coordinated disclosure process and response timelines.
  • Redirects vulnerabilities that actually belong to MediaWiki or Semantic MediaWiki to the right place.

Add a SECURITY.md documenting supported versions, private vulnerability
reporting via GitHub security advisories, and the coordinated disclosure
process. Adapted from the Semantic Scribunto security policy.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant