acteng / update-your-capital-schemes

Update your capital schemes service.
https://update-your-capital-schemes.activetravelengland.gov.uk/
MIT License
4 stars 0 forks source link

Document vulnerability disclosure mechanism #157

Closed Sparrow0hawk closed 2 months ago

Sparrow0hawk commented 2 months ago

The service should have a vulnerability disclosure mechanism. GDS recommend using security.txt.

This involves hosting a small text file on the service either at /security.txt or /.well-known/security.txt

NCSC recommend that we use the following cross-government vulnerability disclosure form - https://vulnerability-reporting.service.security.gov.uk/