clusterlink-net / clusterlink

A Gateway for connecting application services in different domains, networks, and cloud infrastructures
https://clusterlink.net
Other
17 stars 18 forks source link

Create SECURITY.md #604

Closed welisheva22 closed 1 month ago

welisheva22 commented 1 month ago

Given that we are in the alpha stage, I think this would suffice. When we are out of alpha stage, it would be valuable to revise this process as security vulnerabilities may need to be handled differently than other enhancements/bugs/comments.

elevran commented 1 month ago

Not sure we want vulnerabilities reported as normal issues. Need to research what options are available so they can be fixed before disclosed publicly (e.g., maintainers mailing list)

elevran commented 1 month ago

Enabled private vulnerability reporting on the repo. Revised SECURITY.md text to reflect that.