chore: add a formal security policy (SECURITY.md) #2115
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Establishes a formal security policy (
SECURITY.md
) to provide clear guidelines for reporting vulnerabilities and strengthen the project's security posture. This policy creates a structured framework for coordinated vulnerability disclosure, protecting both users and the project.Key Components
Why This Matters
A formal security policy is essential for any production-ready starter kit. It:
Implementation Notes
The policy is placed in
.github/SECURITY.md
which GitHub automatically recognizes and surfaces in:This follows GitHub's recommended practices for coordinated vulnerability disclosure and aligns with the broader JavaScript ecosystem's security standards.