Add proposed security policy#1803
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #1803 +/- ##
=======================================
Coverage 85.15% 85.15%
=======================================
Files 181 181
Lines 12783 12783
Branches 1206 1206
=======================================
Hits 10885 10885
Misses 1715 1715
Partials 183 183
Flags with carried forward coverage won't be shown. Click here to find out more. Continue to review full report in Codecov by Sentry.
🚀 New features to boost your workflow:
|
|
@jminor mentions: |
Signed-off-by: Eric Reinecke <ereinecke@netflix.com>
…d SECURITY.md to MANIFEST.in Signed-off-by: Eric Reinecke <ereinecke@netflix.com>
…rom github runner Signed-off-by: Eric Reinecke <ereinecke@netflix.com>
f9a14b6 to
e24180f
Compare
Signed-off-by: Eric Reinecke <ereinecke@netflix.com>
|
I've set up notifications for emails to the list - when we receive notices we will acknowledge the sender and then proceed based on the nature of the vulnerability and level of effort to fix. |
Fixes #1790
Fixes #1407
Summarize your change.
Adds a
SECURITY.mdfile with basic documentation of how to report vulnerabilities and out security practices.DO NOT MERGE UNTIL security@opentimeline.io is created
To discuss
I matched OpenEXR's response times for vulnerabilities, does that make sense for us?