Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding security.md to sigstore repos #19

Closed
annabellegoth2boss opened this issue Apr 5, 2021 · 4 comments
Closed

Adding security.md to sigstore repos #19

annabellegoth2boss opened this issue Apr 5, 2021 · 4 comments
Assignees

Comments

@annabellegoth2boss
Copy link

With the security policy nested under the Community repo, repos like Rekor show up as "no security policy" -- whomp whomp :(

Could probably just have the security.md's in other repos point to this one so it can serve as the canonical policy.

@lukehinds
Copy link
Member

thanks @annabellegoth2boss , could you show me where it shows "no security policy", is that a github thing?

@annabellegoth2boss
Copy link
Author

"No security policy" was just my shorthand for the result that will come up if someone uses a scanning tool or if they go to the Security tab on the repo (like Rekor's, for example). The concept of "security policy" stops at the repo level on GitHub--no way to apply one security policy to an entire org that I know of.

@lukehinds lukehinds self-assigned this Apr 5, 2021
@lukehinds
Copy link
Member

Fair point, I will add a basic version that points back to the mothership version in community. Thanks for this @annabellegoth2boss

@lukehinds
Copy link
Member

actually I should ask, bit rude of me. Is this something you would like to work on @annabellegoth2boss ?

This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants