Skip to content

add security policy directory#132

Open
Ryun1 wants to merge 2 commits intomainfrom
add-security-policies
Open

add security policy directory#132
Ryun1 wants to merge 2 commits intomainfrom
add-security-policies

Conversation

@Ryun1
Copy link
Copy Markdown
Member

@Ryun1 Ryun1 commented Oct 23, 2025

List of changes

  • Add directory of security policies
  • Add a suggested v1.1 policy

@Ranchhand87
Copy link
Copy Markdown
Contributor

https://github.com/IntersectMBO/Open-Source-Office/security/advisories/new

Please update to reflect this link within the revised Security policy.

CC: @Emmanuel-Tyty @HarunJr

@Ranchhand87
Copy link
Copy Markdown
Contributor

@ThatGuyLLC Please give some thoughts on this.

@Ranchhand87
Copy link
Copy Markdown
Contributor

https://github.com/IntersectMBO/Open-Source-Office/security/advisories/new

Please update to reflect this link within the revised Security policy.

CC: @Emmanuel-Tyty @HarunJr

@Emmanuel-Tyty @HarunJr can one of y'all audit this?

@HarunJr HarunJr requested review from HarunJr and removed request for ThatGuyLLC April 2, 2026 12:28
Copy link
Copy Markdown

@HarunJr HarunJr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for putting this together! The updates look good.

I just caught one minor typo that exists in both of the templates. Other than that it looks good to me.


5. **Fixing Issue**: The team agrees on the fix, the announcement, and the release schedule with the reporter. If the reporter is not responsive in a reasonable time frame this should not block the team from moving to the next steps particularly in the face of a high impact or high severity issue.

a. **Mitigation**: Depending on the severity and criticity of the issue, the team can decide to disclose the issue publicly in the absence of a fix _if and only if_ a clear, simple, and effective mitigation plan is defined. This _must_ include instructions for users and operators of the software, and a time horizon at which the issue will be properly fixed (eg. version number).
Copy link
Copy Markdown

@HarunJr HarunJr Apr 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

On line 53. Change "Depending on the severity and [criticity] of the issue..." to "Depending on the severity and [criticality] of the issue..."

If you discover a security vulnerability in xxxx, we encourage you to
responsibly disclose it to us. To report a vulnerability, please use
the [private reporting form on
GitHub](https://github.com/input-output-hk/mithril/security/advisories/new)
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

typo


- A description of the vulnerability and its potential impact.
- Steps to reproduce the vulnerability.
- The version of `xxxx` package where the vulnerability exists.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

typo


## Introduction

The Cardano open source project (xxx) is committed to ensuring the security of
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

typo

## Contact Information

To report a security vulnerability, please use [GitHub
form]((add project github form for your project)). Should you experience any issues reporting via GitHub or have other questions, Please contact [Security](security@intersectmbo.org).
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

typo


5. **Fixing Issue**: The team agrees on the fix, the announcement, and the release schedule with the reporter. If the reporter is not responsive in a reasonable time frame this should not block the team from moving to the next steps particularly in the face of a high impact or high severity issue.

a. **Mitigation**: Depending on the severity and criticity of the issue, the team can decide to disclose the issue publicly in the absence of a fix _if and only if_ a clear, simple, and effective mitigation plan is defined. This _must_ include instructions for users and operators of the software, and a time horizon at which the issue will be properly fixed (eg. version number).
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

crticality


This Security Vulnerability Disclosure Policy may be updated or
revised as necessary. Please check the latest version of this policy
on the [xxxx repository]((add link for your project)).
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

typo


## Conclusion

The xxxx project greatly appreciates the assistance of the security
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

typo

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants