Skip to content

docs(security): add SECURITY.md with coordinated disclosure guidance - #13

Closed
donny-devops wants to merge 1 commit into
mainfrom
donny-devops-patch-1
Closed

docs(security): add SECURITY.md with coordinated disclosure guidance#13
donny-devops wants to merge 1 commit into
mainfrom
donny-devops-patch-1

Conversation

@donny-devops

Copy link
Copy Markdown
Owner

No description provided.

Copilot AI review requested due to automatic review settings June 21, 2026 06:36
@qodo-code-review

Copy link
Copy Markdown

Qodo reviews are paused for this user.

Troubleshooting steps vary by plan Learn more →

On a Teams plan?
Reviews resume once this user has a paid seat and their Git account is linked in Qodo.
Link Git account →

Using GitHub Enterprise Server, GitLab Self-Managed, or Bitbucket Data Center?
These require an Enterprise plan - Contact us
Contact us →

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a SECURITY.md file to establish the repository's security policy, detailing the scope, supported versions, vulnerability reporting procedures, and a security roadmap. The feedback recommends adding a specific email address for contacting the maintainer directly to ensure the reporting instructions are complete and actionable.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread SECURITY.md
2. Click **Report a vulnerability**.
3. Fill in the details and submit.

Alternatively, you may email the maintainer directly. Include:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The policy mentions the option to email the maintainer directly, but no email address or contact link is provided. Please add the maintainer's email address.

Suggested change
Alternatively, you may email the maintainer directly. Include:
Alternatively, you may email the maintainer directly at security@example.com. Include:

@sonarqubecloud

Copy link
Copy Markdown

@amazon-q-developer amazon-q-developer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review Summary

This PR adds comprehensive security documentation with coordinated disclosure guidance, which is essential for security-adjacent projects. The structure and content are generally well-organized.

Critical Issue Identified:

  • Missing maintainer email address for the alternative reporting method (Line 26)

Assessment:
The SECURITY.md file provides clear guidance on vulnerability reporting, disclosure policies, and scope. Once the email contact information is added, this will provide a complete security reporting framework for the project.


You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.

Comment thread SECURITY.md
2. Click **Report a vulnerability**.
3. Fill in the details and submit.

Alternatively, you may email the maintainer directly. Include:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Missing Critical Information: Add the maintainer's email address. The alternative reporting method instructs users to email the maintainer directly but provides no contact information, breaking this vulnerability reporting pathway.

Suggested change
Alternatively, you may email the maintainer directly. Include:
Alternatively, you may email the maintainer directly at [security@example.com]. Include:

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a repository security policy document to define scope, supported versions, and a coordinated vulnerability disclosure process for Post-Quantum Studio.

Changes:

  • Introduces SECURITY.md describing reporting guidance and disclosure expectations.
  • Defines scope/out-of-scope items and a high-level security roadmap.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread SECURITY.md
2. Click **Report a vulnerability**.
3. Fill in the details and submit.

Alternatively, you may email the maintainer directly. Include:

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fe7cdf66f9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread SECURITY.md
2. Click **Report a vulnerability**.
3. Fill in the details and submit.

Alternatively, you may email the maintainer directly. Include:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Provide a concrete email address for private reports

When GitHub private vulnerability reporting is disabled or unavailable to a reporter, this fallback path is not actionable because it tells reporters to email the maintainer but provides no address or other contact; I checked the repo for contact/email references and only this new SECURITY.md mentions one. Please include a concrete security contact or remove the unusable fallback so vulnerability reports can still be sent privately.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Owner Author

Closing as superseded by #24, which bundles the CI workflow and SECURITY.md. Reopen if needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants