PrimalHQ / primal-web-app

Primal's web app for Nostr, as experienced on primal.net.
https://primal.net
MIT License
200 stars 39 forks source link

Add a SECURITY.md for responsible disclosures #15

Open geeknik opened 1 year ago

geeknik commented 1 year ago

PrimalHQ/primal-web-app currently does not have a SECURITY.md file for reporting security vulnerabilities.

It would be great if you could create a SECURITY.md following GitHub's guidelines:

https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository

This provides instructions for creating a security policy and process for handling vulnerability reports. Having a clear policy helps ensure vulnerabilities are handled properly.

Some key things the SECURITY.md should include:

Adding a SECURITY.md makes it easier for security researchers to responsibly disclose issues they find and helps keep your project secure. Looking forward to having this in place.