Skip to content

Improve security reporting guidelines in SECURITY.md#4823

Open
lukem-ts wants to merge 1 commit intomainfrom
security-reporting-update-poc
Open

Improve security reporting guidelines in SECURITY.md#4823
lukem-ts wants to merge 1 commit intomainfrom
security-reporting-update-poc

Conversation

@lukem-ts
Copy link

@lukem-ts lukem-ts commented Mar 18, 2026

Description:

Updating SECURITY.md to include reporting guidelines.


Note

Low Risk
Low risk documentation-only change that does not modify any runtime code paths or security controls.

Overview
Updates SECURITY.md to add a new Reporting Guidelines section describing what details to include in vulnerability reports (summary, PoC, impact, suggested fix) and clarifies that SSRF/outbound-request findings should be evaluated against the existing policy.

Written by Cursor Bugbot for commit bc1d334. This will update automatically on new commits. Configure here.

@lukem-ts lukem-ts requested a review from a team March 18, 2026 06:47
@CLAassistant
Copy link

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@lukem-ts lukem-ts requested a review from joeleonjr March 18, 2026 06:47
Copy link
Contributor

@joeleonjr joeleonjr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants