Repository navigation
Create AboutCode-level security policy #187
Description
Activity
@hemantchilkuri thank you for your interest, but this is something which will be handled by the maintainers. If you have any suggestions for improvement though please let us know. Also please find other labeled
good first issuefrom projects at https://github.com/aboutcode-org which are great for contributions.@mjherzog I've started a draft at https://github.com/aboutcode-org/.github/blob/main/.github/SECURITY.md
@LuciferVid we have started a draft at https://github.com/aboutcode-org/.github/blob/main/.github/SECURITY.md and because this is a github org-specific defaults repo this is now included in all the
aboutcode-orgrepos. See for example: https://github.com/aboutcode-org/scancode-toolkit/?tab=security-ov-fileIf you have suggestions to improve and update this, please open a PR and we can review the details there.
I would like to work on this task.
Before I begin, I want to confirm a few details to ensure the security policy aligns with AboutCode.org standards and expectations:
- Should the policy follow a structure similar to GitHub’s
SECURITY.mdtemplate or would you prefer a more detailed policy (like AboutCode.org’s comprehensive version)? - Should the policy include:
- vulnerability reporting process,
- supported versions,
- disclosure timelines,
- researcher guidelines,
- contact channels,
- coordinated disclosure practices?
- Will this security policy be added to all repositories within the organization (and referenced from each), or should it be created centrally and linked from individual repos?
- Do you prefer the initial draft as a PR directly, or should I share the outline first for review?
Once I have your guidance, I can prepare a complete and clean
SECURITY.mdthat meets all requirements.Thanks!
- Should the policy follow a structure similar to GitHub’s
AboutCode.org Security Policy
🛡️ Purpose
AboutCode.org is committed to safe and secure open source software. This security policy describes:
- how to report vulnerabilities
- how we handle security issues
- how we update and protect our codebases
This policy applies to all AboutCode.org projects unless otherwise stated.
📬 Reporting a Vulnerability
Please report vulnerabilities privately so we can address them before public disclosure.
Email: security@aboutcode.org
(Use this email exclusively for vulnerability reports and include all necessary technical detail.)Required fields in your report:
- Package/project name & version
- Detailed description
- Steps to reproduce / PoC
- Impact / severity
- Suggested fix (if available)
- Contact info for follow-up
Upon receiving a report, we will:
- Acknowledge receipt within 48 hours
- Validate the report and reproduce the issue
- Coordinate a fix and advisory timeline
⚠️ Never disclose a vulnerability publicly before the team has had a reasonable chance to assess and fix it.
🗂 Severity Classification
We apply a modified CVSS-like scale:
Level Description Response Critical Remote execution, major data loss Fix within 7 days High Privilege escalation, major component risk Fix within 30 days Medium Low risk impact or hard exploitation Within next minor release Low Minimal or unlikely impact Monitored
🛠 Fixing a Reported Issue
After validating a report:
- We assign a maintainer & timeline
- Communicate status to the reporter
- Prepare coordinated patch and release notes
- When applicable, coordinate with major ecosystem registries
We may request additional info if needed.
📢 Coordinated Disclosure
We follow a coordinated disclosure process:
- Fix committed on private branch
- Security advisory drafted
- Advisory published as the patch/release goes public
- Credit to the reporter, unless they request anonymity
🔐 Security Best Practices (Static)
All projects should follow the OSS Security Principles:
- Minimal necessary permissions
- Regular dependencies audit
- Signed releases (where feasible)
- Security testing during CI/CD
- Automated vulnerability scanning
👉 See the OpenSSF Principles for more:
https://repos.openssf.org/principles-for-package-repository-security
📎 Tools & Services We Use
We leverage:
- GitHub Security Features
- Dependabot alerts & updates
- Security advisories
- Secret scanning (where available)
- Code scanning with custom rules
More: https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository
📌 Policy Updates
This policy is reviewed annually and updated as needed.
Last review date: YYYY-MM-DD
Hi, I’d like to work on drafting the AboutCode-level security policy (SECURITY.md) based on GitHub and OpenSSF best practices. Please let me know if that works.
- added a commit that references this issue
on Jan 13, 2026 Hey maintainers 👋 I’ve submitted a PR fixing this issue.
Would love your feedback.- addedpolicyFor issues related to aboutcode-wide policiesFor issues related to aboutcode-wide policies
on Feb 26, 2026
We need to create an AboutCode.org level security policy and reference it on each of our projects.
Some useful resources (GH context) are: