MikeMcl / decimal.js

An arbitrary-precision Decimal type for JavaScript
http://mikemcl.github.io/decimal.js
MIT License
6.35k stars 480 forks source link

Create a security policy #226

Open joycebrum opened 1 year ago

joycebrum commented 1 year ago

Hi, I'd like to suggest to create a Security Policy for decimal.js project. It is a GitHub standard document (SECURITY.md) that can be found in the "Security Tab" to instruct users how to report vulnerabilities in a safe and efficient way.

It is a Scorecard Recommendation (being a security measure of medium priority) and a Github Recommendation.

Together with this issue I'll submit one suggestion of Security Policy, feel free to edit it directly or ask me for editions until it is in compliance with how you would best handle vulnerability reports.

Disclosure: I'm from Google (the Google Open Source Security Team) and I'm working on contributing to many open source projects to increase their supply-chain security

MikeMcl commented 1 year ago

Okay, thanks Joyce. I will look at this next week.