Add a Security policy file#1013
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✅ Files skipped from review due to trivial changes (1)
📝 WalkthroughWalkthroughA new Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes 🚥 Pre-merge checks | ✅ 2✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Comment |
6afc432 to
3d7912b
Compare
|
@Mergifyio queue |
|
|
@Mergifyio rebase |
This was identified as missing when assessing the fromager repository with OpenSSF's scorecard. See python-wheel-build#1008. Signed-off-by: Martin Prpič <mprpic@redhat.com>
✅ Branch has been successfully rebased |
3d7912b to
6fd4efe
Compare
Pull Request Description
What
This was identified as missing when assessing the fromager repository with OpenSSF's scorecard. See #1008.
Why
A security policy file tells potential contributors how to privately disclose vulnerabilities. GitHub offers a native "report a vulnerability" button (maybe this needs to be configured at the repo level by admins?). If using GitHub is not desired, we could set up a mailing list or point people to Red Hat Product Security (secalert@redhat.com) since this projects is largely maintained by Red Hatters right now.