Skip to content

Commit

Permalink
Adds details on security documentation (#3854)
Browse files Browse the repository at this point in the history
* Docs: adds i18n link and changes redaction (s/we/you/)

* Docs: moving files to advanced folder

* Security: adds GPG key for security [at] decidim.org

* Security: adds a check for default users on checklist

* Fixes codeclimate errors on CONTRIBUTING.md doc
  • Loading branch information
andreslucena authored and mrcasals committed Jul 16, 2018
1 parent 03d0e1a commit 622f7b5
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 1 deletion.
6 changes: 5 additions & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,11 @@ If you haven't already, come find us in [Gitter](https://gitter.im/decidim/decid

## Did you find a bug?

* **Do not open up a GitHub issue if the bug is a security vulnerability in Decidim**, and instead send us an email to security [at] decidim.org.
* **Do not open up a GitHub issue if the bug is a security vulnerability in Decidim**, and instead send us an email to security [at] decidim.org. We recommend to use GPG for these kind of communications, the fingerprint is C1BD 8981 D83C 23F9 D419 FE42 149A D0F9 84B9 35C4. To download our key:

```bash
gpg --keyserver pgp.key-server.io --recv 84B935C4
```

* **Ensure the bug was not already reported** by searching on GitHub under [Issues](https://github.com/decidim/decidim/issues).

Expand Down
2 changes: 2 additions & 0 deletions docs/checklist.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,8 @@ As a technopolitical project, Decidim needs several things to work. This is a no

1. If you want, configure your [**social providers**](https://github.com/decidim/decidim/blob/master/docs/services/social_providers.md) to enable login using external applications.

1. Check that you don't have any **default users, emails and passwords**, neither on the admin or on the system panel.

## Contents

1. Ideally you'll have a **Team** formed with experts on IT, Communication, Participation, Design and Law.
Expand Down

0 comments on commit 622f7b5

Please sign in to comment.