AcademySoftwareFoundation / OpenTimelineIO

Open Source API and interchange format for editorial timeline information.
http://opentimeline.io
Apache License 2.0
1.47k stars 294 forks source link

Set up a project security policy #1790

Open cary-ilm opened 2 months ago

cary-ilm commented 2 months ago

Copy SECURITY.md from OpenEXR or one of the other ASWF projects, and delete whatever doesn't apply to your project. This cover several of the OpenSSF badge requirements, like the policy, vulnerability reporting, and expectations.

Other related steps to take:

  1. Set up security@opentimelineio.org that forwards to your technical steering committee. The LF can help configure this.
  2. On the "Code security & analysis" page of your GitHub repo settings, enable private vulnerability reporting.