Skip to content

Minimal SECURITY.md which is expected in github repos#936

Closed
schneidergithub wants to merge 1 commit into
docker:mainfrom
schneidergithub:patch-1
Closed

Minimal SECURITY.md which is expected in github repos#936
schneidergithub wants to merge 1 commit into
docker:mainfrom
schneidergithub:patch-1

Conversation

@schneidergithub
Copy link
Copy Markdown

A simple security policy, since I'm sure the owners of the repo will want to update this.

A simple security policy, since I'm sure the owners of the repo will want to update this.
Copy link
Copy Markdown
Contributor

@sourcery-ai sourcery-ai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue, and left some high level feedback:

  • Consider clarifying the scope of this policy (e.g., which projects or components are covered) so reporters know whether this contact applies to their finding.
  • It would be helpful to include expected response timelines or what reporters can generally expect after contacting security@docker.com (acknowledgment, triage, etc.).
  • If there are preferred formats or details for vulnerability reports (e.g., steps to reproduce, impact assessment), mentioning them here can improve report quality and reduce back-and-forth.
Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- Consider clarifying the scope of this policy (e.g., which projects or components are covered) so reporters know whether this contact applies to their finding.
- It would be helpful to include expected response timelines or what reporters can generally expect after contacting security@docker.com (acknowledgment, triage, etc.).
- If there are preferred formats or details for vulnerability reports (e.g., steps to reproduce, impact assessment), mentioning them here can improve report quality and reduce back-and-forth.

## Individual Comments

### Comment 1
<location path="SECURITY.md" line_range="5" />
<code_context>
+
+## Reporting a Vulnerability
+
+Do not report vulnerabilities publicly, please contact security@docker.com 
</code_context>
<issue_to_address>
**suggestion (typo):** Consider fixing the comma splice and adding proper sentence-ending punctuation.

This sentence joins two independent clauses with only a comma. Consider either: "Do not report vulnerabilities publicly. Please contact security@docker.com." or "Do not report vulnerabilities publicly; please contact security@docker.com."
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

Comment thread SECURITY.md
Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a SECURITY.md file to establish a security policy, providing instructions for reporting vulnerabilities privately via email. I have no feedback to provide.

@ericcurtin ericcurtin closed this May 23, 2026
@schneidergithub
Copy link
Copy Markdown
Author

schneidergithub commented May 23, 2026

@ericcurtin - I'm curious why this was closed? There is no security.md file, and at a bare minimum an email address would be useful to know, so people (like me) can submit security reports responsibly. I imagine a likely scenario is someone posting publicly a vulnerability in the repo's issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants