Polymer / polymer

Our original Web Component library.
https://polymer-library.polymer-project.org/
BSD 3-Clause "New" or "Revised" License
22.05k stars 2.01k forks source link

Create a Security Policy #5723

Open joycebrum opened 6 months ago

joycebrum commented 6 months ago

Description

Hi, I'm from Google Open Source Security Team and I'd like to suggest to create a Security Policy for the repository.

A Security Policy is a GitHub standard document (SECURITY.md) that can be found in the "Security Tab" to instruct users how to report vulnerabilities in a safe and efficient way.

It is a Scorecard Recommendation (being a security measure of medium priority) and a Github Recommendation.

Together with this issue I'll submit one suggestion of Security Policy, feel free to edit it directly or ask me for editions until it is in compliance with how would best handle vulnerability reports.

Live Demo

It would appear in the Security Dashboard and in the About section:

image