Skip to content

Add SECURITY.md for vulnerability reporting - #333

Open
goneall wants to merge 4 commits into
masterfrom
security-md
Open

goneall wants to merge 4 commits into
masterfrom
security-md

Conversation

@goneall

@goneall goneall commented Sep 29, 2026

Copy link
Copy Markdown
Member

Added a security policy outlining reporting mechanisms for vulnerabilities and response processes.

The security policy is a modified version initially drafted by Gemini AI with the addition of the LF recommended CRA statement for LF projects which do not have an assigned steward(s).

Added a security policy outlining reporting mechanisms for vulnerabilities and response processes.
@bact bact added the documentation Improvements or additions to documentation label Sep 29, 2026
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md
Comment thread SECURITY.md
Comment thread SECURITY.md
Comment thread SECURITY.md
goneall and others added 3 commits September 30, 2026 18:11
Co-authored-by: Arthit Suriyawongkul <arthit@gmail.com>
Co-authored-by: Arthit Suriyawongkul <arthit@gmail.com>
Co-authored-by: Arthit Suriyawongkul <arthit@gmail.com>
Comment thread SECURITY.md
Comment on lines +11 to +12
Instead, please send a confidential email with details of the vulnerability and a reference to this tool-java repository to:
[spdx-tools-security@lists.spdx.org](mailto:spdx-tools-security@lists.spdx.org)

@bact bact Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Instead, please send a confidential email with details of the vulnerability and a reference to this tool-java repository to:
[spdx-tools-security@lists.spdx.org](mailto:spdx-tools-security@lists.spdx.org)
Instead, please send a confidential email with details of the vulnerability and a reference to this `tools-java` repository to:
<spdx-tools-security@lists.spdx.org>.
This is a private, restricted mailing list accessible only to authorized security maintainers.

@goneall what about this?

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants