Skip to content

Create SECURITY.md for security policy - #4

Merged
lisagorewitdecker merged 3 commits into
masterfrom
lisagorewitdecker-patch-1
Sep 2, 2026
Merged

lisagorewitdecker merged 3 commits into
masterfrom
lisagorewitdecker-patch-1

Conversation

@lisagorewitdecker

Copy link
Copy Markdown
Member

Added a security policy document outlining supported versions and vulnerability reporting.

Added a security policy document outlining supported versions and vulnerability reporting.

Signed-off-by: lisagorewitdecker <50784106+lisagorewitdecker@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings August 27, 2026 19:52

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a SECURITY.md document intended to define the project’s supported versions and the process for reporting security vulnerabilities.

Changes:

  • Introduces SECURITY.md with sections for supported versions and vulnerability reporting guidance.
Suppressed comments (1)

SECURITY.md:21

  • The Reporting a Vulnerability section is placeholder template text. SECURITY.md should specify a concrete private reporting channel (e.g., GitHub private vulnerability reporting) and set expectations for response/triage so reporters know what to do.
Use this section to tell people how to report a vulnerability.

Tell them where to go, how often they can expect to get an update on a
reported vulnerability, what to expect if the vulnerability is accepted or
declined, etc.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread SECURITY.md Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: lisagorewitdecker <50784106+lisagorewitdecker@users.noreply.github.com>
@lisagorewitdecker

Copy link
Copy Markdown
Member Author

@copilot Fix the code for all comments in this review thread.

When a review comment includes a suggested change, apply the suggestion exactly.

Do not make changes beyond what is described in the linked review thread.

…h actual guidance

Co-authored-by: lisagorewitdecker <50784106+lisagorewitdecker@users.noreply.github.com>

Copilot AI commented Aug 31, 2026

Copy link
Copy Markdown

@copilot Fix the code for all comments in this review thread.

When a review comment includes a sugge...

Fixed in the latest commit. The placeholder "Reporting a Vulnerability" text has been replaced with actual guidance (how to report, expected response time, and what to expect for accepted/declined vulnerabilities). The Supported Versions table already used project-appropriate versioning ("latest" / "< latest") rather than the example 5.x/4.x values.

@lisagorewitdecker
lisagorewitdecker merged commit a12c220 into master Sep 2, 2026
6 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants