Skip to content

Coordinated disclosure guide #84

Description

@truthixify

Extra labels: writing, security
Tier: S (1-2 days) | Type: writing

Context. No public disclosure guide today. Researchers who find a bug don't know how to report responsibly.

Scope.

  • New reference/security-disclosure.mdx (also cross-committed as SECURITY.md in each repo).
  • Contact address(es).
  • What qualifies as in-scope.
  • Response SLA.
  • Safe-harbor language.
  • Recognition + reward posture.

Acceptance.

  • Doc lands + SECURITY.md links to it from each repo root
  • Reviewed by whoever holds the security email

Files. reference/security-disclosure.mdx (new), per-repo SECURITY.md.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Stellar WaveIssues in the Stellar wave programdocsDocumentationdripsFunded via Drips Networkhelp wantedExtra attention is neededsecuritySecurity-sensitive workwriting

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions