-
Notifications
You must be signed in to change notification settings - Fork 56
Open
Labels
enhancementNew feature or requestNew feature or request
Description
Desired Behavior
Need to leverage GitHub scanning / dependabot v2.
Need to have a SECURITY.md file so that contributors are aware of all KNOWN KNOWNS and KNOWN UNKNOWNS.
At a minimum:
- Security Policy
- Security Advisories
- Dependabot Alerts
- Code Scanning
Benefits
- Users will have a report of clear list of actions taken on security reports issued by agencies AND
- Contributors have a clear process on how to take action on vulnerability alerts.
- Both Users and Contributors can TRUST the software to be as free as possible from known vulnerabilities
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request
