Skip to content

Add SECURITY.md with vulnerability disclosure policy#41

Open
syntexsecurity wants to merge 1 commit intoEuro-Office:mainfrom
syntexsecurity:security-policy
Open

Add SECURITY.md with vulnerability disclosure policy#41
syntexsecurity wants to merge 1 commit intoEuro-Office:mainfrom
syntexsecurity:security-policy

Conversation

@syntexsecurity
Copy link
Copy Markdown

Euro-Office currently has no documented process for reporting security vulnerabilities. This adds a SECURITY.md establishing:

  • Reporting channels (GitHub security advisories + maintainer email)
  • What to include in a report
  • Response timeline commitments (48hr acknowledgment, 7-day assessment)
  • Coordinated disclosure process
  • Scope covering all repositories in the organization
  • Note on inherited upstream OnlyOffice CVEs

One new file at the repo root. No code changes.

Establishes a responsible disclosure process for the Euro-Office
project, covering all repositories in the organization. Includes
guidance on reporting methods (GitHub security advisories or email),
expected response timelines, and a note about upstream OnlyOffice
CVE coverage.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant