Skip to content

fix: add SECURITY.md with formal VDP and triage SLA - #217

Open
rafaio1 wants to merge 1 commit into
MixinNetwork:masterfrom
rafaio1:fix/add-security-policy-and-sla
Open

rafaio1 wants to merge 1 commit into
MixinNetwork:masterfrom
rafaio1:fix/add-security-policy-and-sla

Conversation

@rafaio1

@rafaio1 rafaio1 commented Aug 24, 2026

Copy link
Copy Markdown

Summary

This PR introduces a formal SECURITY.md file to establish a clear Vulnerability Disclosure Policy (VDP) and explicit Service Level Agreements (SLAs) for security researchers.

This addresses the concerns raised in #216 regarding the lack of communication and triage timelines for privately submitted GitHub Security Advisories (GHSAs). While filtering spam and AI-generated reports is necessary, legitimate and critical vulnerabilities require a structured and responsive process.

Changes

  • Added SECURITY.md to the repository root.
  • Defined clear instructions for reporting vulnerabilities via GHSA.
  • Established strict SLAs:
    • Acknowledgment: Within 48 hours of submission.
    • Triage & ETA: Within 5 business days.
  • Documented the Bug Bounty Program rules and scope regarding the up to $1,000,000 reward tier.
  • Outlined expectations for responsible disclosure.

By merging this PR, the maintainers commit to these SLAs, ensuring that future security reports are handled professionally and transparently, restoring researcher confidence in the disclosure process.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant