Skip to content

Add a SECURITY.md file.#150

Merged
sanason merged 3 commits intomasterfrom
add-security-policy
Dec 30, 2024
Merged

Add a SECURITY.md file.#150
sanason merged 3 commits intomasterfrom
add-security-policy

Conversation

@sanason
Copy link
Copy Markdown
Member

@sanason sanason commented Dec 9, 2024

Copied the boilerplate SECURITY.md file from the Allstar repo. I omitted the section about bug bounties since DAP doesn't participate in the bug bounty program. Although, that wouldn't be a bad idea...

I decided not to follow the Allstar version's recommendation to route reporting through GSA's VDP. As far as I can tell, GSA will not give TTS development teams access to manage reports for their own properties in HackerOne. Also, I sent an email to gsa-vulnerability-reports@gsa.gov and haven't received a response. The GSA VDP feels like a black hole to me. If it proves itself otherwise, I'll consider updating this policy.

Fixes #139.

@sanason sanason marked this pull request as draft December 11, 2024 16:16
levinmr
levinmr previously approved these changes Dec 11, 2024
@levinmr
Copy link
Copy Markdown
Contributor

levinmr commented Dec 11, 2024

The only minor thing I see in here is that the GSA vulnerability disclosure policy is linked twice, and the links are slightly different.

@sanason sanason marked this pull request as ready for review December 16, 2024 18:42
@sfrederick-gsa-gov
Copy link
Copy Markdown

Having vulnerabilities reported directly to the Analytics.usa.gov/DAP team is not really a good idea.

I have been in touch w/ the GSA VDP team. We may be able to get access to the VDP findings directly. Let me have some more time to work on this, please.

@sanason
Copy link
Copy Markdown
Member Author

sanason commented Dec 16, 2024

Having vulnerabilities reported directly to the Analytics.usa.gov/DAP team is not really a good idea.

Why not? @sfrederick-gsa-gov

@sfrederick-gsa-gov
Copy link
Copy Markdown

No GSA Vulnerability Reporting and Tracking. Without a dedicated team, things tend to get lost in the shuffle.

@sanason sanason merged commit 33324d0 into master Dec 30, 2024
@sanason sanason deleted the add-security-policy branch January 9, 2026 14:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Policy violation SECURITY.md

3 participants