Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: update security policy details #1342

Merged
merged 1 commit into from
Jun 8, 2019
Merged

fix: update security policy details #1342

merged 1 commit into from
Jun 8, 2019

Conversation

lirantal
Copy link
Member

@lirantal lirantal commented Jun 8, 2019

New security policy addresses:

  1. Intro to a Responsible Security Disclosure policy
  2. Establish Security Processes
  3. Adopt a Responsible Security Disclosure policy

The most notable changes from your current policy is removal of the following:

  • promise - due to the nature of the project being open source, I think it is not very feasible to put an actual number of days as theoretically speaking the project’s team could be out on holiday or vacation. it also conflicts with the SLA of other programs which are mentioned like Snyk or npm because these have their own timeframe and processes set in place which is beyond your control
  • rules for reporting - some of them go without mentioning, and some statements there relate more with online services which require no modification of the website, etc.

Copy link
Member

@juanpicado juanpicado left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 👍 👍 👍 👍 👍 👍 👍 👍 👍 👍

@juanpicado juanpicado merged commit ddcd89d into verdaccio:master Jun 8, 2019
@juanpicado
Copy link
Member

Thanks Liran !!

@lock
Copy link

lock bot commented Jun 29, 2019

🤖This thread has been automatically locked 🔒 since there has not been any recent activity after it was closed.
We lock tickets after 90 days with the idea to encourage you to open a ticket with new fresh data and to provide you better feedback 🤝and better visibility 👀.
If you consider, can attach this ticket 📨to the new one as a reference for better context.
Thanks for being a part of the Verdaccio community! 💘

@lock lock bot locked as resolved and limited conversation to collaborators Jun 29, 2019
@lirantal lirantal deleted the lirantal-security-policy branch July 7, 2019 23:48
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants