Skip to content

Create AboutCode-level security policy #187

Activity

  1. AyanSinhaMahapatra commented on Mar 31, 2025

    @AyanSinhaMahapatra
    Member

    @hemantchilkuri thank you for your interest, but this is something which will be handled by the maintainers. If you have any suggestions for improvement though please let us know. Also please find other labeled good first issue from projects at https://github.com/aboutcode-org which are great for contributions.

    @mjherzog I've started a draft at https://github.com/aboutcode-org/.github/blob/main/.github/SECURITY.md

  2. AyanSinhaMahapatra commented on Jul 17, 2025

    @AyanSinhaMahapatra
    Member

    @LuciferVid we have started a draft at https://github.com/aboutcode-org/.github/blob/main/.github/SECURITY.md and because this is a github org-specific defaults repo this is now included in all the aboutcode-org repos. See for example: https://github.com/aboutcode-org/scancode-toolkit/?tab=security-ov-file

    If you have suggestions to improve and update this, please open a PR and we can review the details there.

  3. Rohankaf commented on Nov 14, 2025

    @Rohankaf

    Hi @AyanSinhaMahapatra

    I would like to work on this task.

    Before I begin, I want to confirm a few details to ensure the security policy aligns with AboutCode.org standards and expectations:

    1. Should the policy follow a structure similar to GitHub’s SECURITY.md template or would you prefer a more detailed policy (like AboutCode.org’s comprehensive version)?
    2. Should the policy include:
      • vulnerability reporting process,
      • supported versions,
      • disclosure timelines,
      • researcher guidelines,
      • contact channels,
      • coordinated disclosure practices?
    3. Will this security policy be added to all repositories within the organization (and referenced from each), or should it be created centrally and linked from individual repos?
    4. Do you prefer the initial draft as a PR directly, or should I share the outline first for review?

    Once I have your guidance, I can prepare a complete and clean SECURITY.md that meets all requirements.

    Thanks!

  4. ChinmayaBiswal7 commented on Dec 24, 2025

    @ChinmayaBiswal7

    @mjherzog

    AboutCode.org Security Policy

    🛡️ Purpose

    AboutCode.org is committed to safe and secure open source software. This security policy describes:

    • how to report vulnerabilities
    • how we handle security issues
    • how we update and protect our codebases

    This policy applies to all AboutCode.org projects unless otherwise stated.


    📬 Reporting a Vulnerability

    Please report vulnerabilities privately so we can address them before public disclosure.

    Email: security@aboutcode.org
    (Use this email exclusively for vulnerability reports and include all necessary technical detail.)

    Required fields in your report:

    • Package/project name & version
    • Detailed description
    • Steps to reproduce / PoC
    • Impact / severity
    • Suggested fix (if available)
    • Contact info for follow-up

    Upon receiving a report, we will:

    1. Acknowledge receipt within 48 hours
    2. Validate the report and reproduce the issue
    3. Coordinate a fix and advisory timeline

    ⚠️ Never disclose a vulnerability publicly before the team has had a reasonable chance to assess and fix it.


    🗂 Severity Classification

    We apply a modified CVSS-like scale:

    Level Description Response
    Critical Remote execution, major data loss Fix within 7 days
    High Privilege escalation, major component risk Fix within 30 days
    Medium Low risk impact or hard exploitation Within next minor release
    Low Minimal or unlikely impact Monitored

    🛠 Fixing a Reported Issue

    After validating a report:

    • We assign a maintainer & timeline
    • Communicate status to the reporter
    • Prepare coordinated patch and release notes
    • When applicable, coordinate with major ecosystem registries

    We may request additional info if needed.


    📢 Coordinated Disclosure

    We follow a coordinated disclosure process:

    1. Fix committed on private branch
    2. Security advisory drafted
    3. Advisory published as the patch/release goes public
    4. Credit to the reporter, unless they request anonymity

    🔐 Security Best Practices (Static)

    All projects should follow the OSS Security Principles:

    • Minimal necessary permissions
    • Regular dependencies audit
    • Signed releases (where feasible)
    • Security testing during CI/CD
    • Automated vulnerability scanning

    👉 See the OpenSSF Principles for more:
    https://repos.openssf.org/principles-for-package-repository-security


    📎 Tools & Services We Use

    We leverage:

    • GitHub Security Features
      • Dependabot alerts & updates
      • Security advisories
      • Secret scanning (where available)
      • Code scanning with custom rules

    More: https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository


    📌 Policy Updates

    This policy is reviewed annually and updated as needed.

    Last review date: YYYY-MM-DD

  5. shriv-cpu commented on Jan 5, 2026

    @shriv-cpu

    Hi, I’d like to work on drafting the AboutCode-level security policy (SECURITY.md) based on GitHub and OpenSSF best practices. Please let me know if that works.

  6. im-anishraj commented on Jan 13, 2026

    @im-anishraj

    Hey maintainers 👋 I’ve submitted a PR fixing this issue.
    Would love your feedback.

  7. added
    policyFor issues related to aboutcode-wide policies
    on Feb 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationpolicyFor issues related to aboutcode-wide policies

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions