Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add email address for reporting security issues #2835

Merged
merged 1 commit into from
Apr 4, 2023

Conversation

stevenengler
Copy link
Contributor

Currently if you click github's "view security policy" button, it brings you to a page that says "Non-goal: Security", which probably isn't the best way to present our security policy :)

This PR adds a small section with an email address for people to report security issues. While we don't really care about the shadow code security specifically (the simulation runs arbitrary code anyways), we do care about things like if we accidentally checked-in a key to the repository, or if we have a security issue in our CI workflows, or if one of shadow's dependencies becomes malicious.

This copies the email address from the code of conduct.

@stevenengler stevenengler added this to the Documentation milestone Apr 3, 2023
@stevenengler stevenengler self-assigned this Apr 3, 2023
@github-actions github-actions bot added the Component: Documentation In-repository documentation, under docs/ label Apr 3, 2023
@stevenengler stevenengler merged commit b00636e into shadow:main Apr 4, 2023
26 checks passed
@stevenengler stevenengler deleted the update-security-doc branch April 4, 2023 18:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Component: Documentation In-repository documentation, under docs/
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants