Skip to content

docs: add security escalation policy#1810

Merged
Krinkle merged 2 commits intoqunitjs:mainfrom
UlisesGascon:patch-1
Jan 31, 2026
Merged

docs: add security escalation policy#1810
Krinkle merged 2 commits intoqunitjs:mainfrom
UlisesGascon:patch-1

Conversation

@UlisesGascon
Copy link
Contributor

👋 Hi everyone! We’re @UlisesGascon and @RafaelGSS, working with the OpenJS Foundation as part of the Alpha-Omega initiative. Our focus is supporting OpenJS projects in strengthening their security posture. We can help with things like:

  • Reviewing or creating security documentation (e.g., SECURITY.md, incident response plans...)
  • Supporting vulnerability handling and escalation (reporting, triage, CVEs, disputes)
  • Reviewing repo configurations and GitHub security settings
  • Sharing best practices (e.g., OSSF Scorecard)
  • Answering general questions on licenses, compliance, or incident response

✨ We’re here as a resource for the QUnit team and happy to collaborate on whatever is most useful for you. Looking forward to working together!

References:

@Krinkle
Copy link
Member

Krinkle commented Jan 30, 2026

I suspect this phrasing came from a general OpenJS webpage or document. I've removed "if you cannot find a private security contact", because the contact is above it in the same document. I've also rephrased it in first person because the grammar felt odd when read in context of the Security policy, as presented within the QUnit project itself.

@UlisesGascon
Copy link
Contributor Author

The current changes are fine. @Krinkle thanks for update the PR 👍

@Krinkle Krinkle merged commit a76c166 into qunitjs:main Jan 31, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants