We should adopt a security policy for Junction, something like a SECURITY.md file. The essential points that need to be outlined in it are:
- Rules of engagement (like don't test on prod!)
- What counts as a bug (it could be a feature :))
- Reporting a bug (who to contact, report template)
This is in relation to #583, which I wasn't too happy about reporting via an issue, but I didn't know better.
Thoughts?
We should adopt a security policy for Junction, something like a
SECURITY.mdfile. The essential points that need to be outlined in it are:This is in relation to #583, which I wasn't too happy about reporting via an issue, but I didn't know better.
Thoughts?