Join our community: https://t.me/+DOylgFv1jyJlNzM0
Why this matters
.github/ISSUE_TEMPLATE/security.md guides reporters on how to file a security issue, but doesn't set expectations for how quickly the maintainers will acknowledge or respond. Security researchers commonly expect a stated SLA (e.g. "we aim to acknowledge within 48 hours") before deciding whether to report publicly or wait.
Acceptance criteria
Files to touch
.github/ISSUE_TEMPLATE/security.md
SECURITY.md
Out of scope
- Setting up a bug bounty program
- Automating SLA tracking
Why this matters
.github/ISSUE_TEMPLATE/security.mdguides reporters on how to file a security issue, but doesn't set expectations for how quickly the maintainers will acknowledge or respond. Security researchers commonly expect a stated SLA (e.g. "we aim to acknowledge within 48 hours") before deciding whether to report publicly or wait.Acceptance criteria
SECURITY.mdSECURITY.mdso the two documents don't contradict each otherFiles to touch
.github/ISSUE_TEMPLATE/security.mdSECURITY.mdOut of scope