🔒️ Add security guidelines for vulnerability disclosure.#51
🔒️ Add security guidelines for vulnerability disclosure.#51JSKitty merged 5 commits intoVectorPrivacy:masterfrom
Conversation
Added a security policy for vulnerability disclosure guidelines. Requires an e-mail address and setting up the Private Security Disclosure system on GitHub.
Removed 'Secure storage of messages' from security considerations. (As Vector doesn't store the messages)
Updated the security contact email to the new domain.
|
Thank you for catching this and filling the gap. As I shared, we had it for the Vector SDK thanks to @Luke-Larsen, but appreciate you spotting this and adding the solution, @selkij! Will have @JSKitty review to make sure everything is up to standard before pushing. |
|
To tighten up around the clock, I've gone and setup all Best Practice repository security precautions and services that I could; and I'll also setup some of my own (automated PR audits) shortly, the final piece of the puzzle is the Disclosure Policy, which you've gracefully provided us, really do appreciate this nudge and writing! 🙏
This PR is absolutely solid, I believe there's only two small additions I'd like before merging, open to discussion, of course;
That aside, beautiful first PR contribution. 🙏 💚 |
- Added a compensation section to clarify the project's current stance on financial rewards for disclosures. - Added another e-mail for reporting a vulnerability.
|
Does this look good ? You can tell me directly what to change by using the reviewing GitHub feature. |
|
It can be merged then! |

Added a security policy for vulnerability disclosure guidelines. Requires an e-mail address and setting up the Private Security Disclosure system on GitHub.