slsa-framework / slsa-verifier

Verify provenance from SLSA compliant builders
Apache License 2.0
226 stars 48 forks source link

docs: Propose a security policy #710

Closed trishankatdatadog closed 1 year ago

trishankatdatadog commented 1 year ago

Propose a security policy (largely borrowed from go-tuf) that users should consult in order to report any security vulnerability.

Note that privately reporting security vulnerabilities requires turning on a GitHub setting.

trishankatdatadog commented 1 year ago

Note that privately reporting security vulnerabilities requires turning on a GitHub setting.

Please don't forget the enable this setting 🙂

ianlewis commented 1 year ago

Please don't forget the enable this setting 🙂

The setting is enabled.