OpenRailAssociation / technical-committee

Landing place for all things related to the Technical Committee of the OpenRail Association
Creative Commons Attribution 4.0 International
4 stars 6 forks source link

Add criteria for security review and policies for incubation stage 2 #148

Open cornelius opened 2 weeks ago

cornelius commented 2 weeks ago

Having a well-defined way how to deal with security issues in dependencies and the project itself is an important quality factor. This is why we should require that for incubation stage 2. This includes setting up automatic checks for vulnerabilities in dependencies as well as documenting a policy for reporting security issues in a SECURITY.md file.