Open
Description
#SecuritySlam
What would you like to be cleaned:
When the SECURITY-INSIGHTS.yml file was initially created in #1469, the in-scope / out-scope subsections of the vulnerability-reporting section were omitted, as it was not entirely clear which of the OWASP Top 10 were in/out of scope. Someone with more knowledge of the project should update the SECURITY-INSIGHTS.yml file to include this section.
Why is this needed:
Adding this section will improve the project's score on the CLOMonitor site.
/sig release