-
Notifications
You must be signed in to change notification settings - Fork 109
Closed
Description
👋 Hello Team!
I noticed there’s no SECURITY.md file in the repo, and I’d like to suggest adding one along with enabling some native GitHub security features.
🔍 Observations:
- No guidance on how to report vulnerabilities
- No .gitignore coverage for potential sensitive files
- GitHub security alerts and secret scanning may not be enabled
✅ Suggested Improvements: - Create a SECURITY.md with reporting instructions and contact details
- Expand .gitignore to exclude env files and sensitive configs
- Enable GitHub secret scanning and Dependabot alerts
💡 Why This Helps:
Security transparency builds trust and protects contributors and users. I’d be happy to draft the initial file and help configure these features.
Please assign this issue to me.
Metadata
Metadata
Assignees
Labels
Type
Projects
Status
Done