Skip to content

[Docs] .github/ISSUE_TEMPLATE/security.md does not state an expected response-time SLA #1091

Description

@grantfox-oss

Join our community: https://t.me/+DOylgFv1jyJlNzM0

Why this matters

.github/ISSUE_TEMPLATE/security.md guides reporters on how to file a security issue, but doesn't set expectations for how quickly the maintainers will acknowledge or respond. Security researchers commonly expect a stated SLA (e.g. "we aim to acknowledge within 48 hours") before deciding whether to report publicly or wait.

Acceptance criteria

  • Add a stated acknowledgment/response time expectation, consistent with SECURITY.md
  • Cross-check wording matches SECURITY.md so the two documents don't contradict each other

Files to touch

  • .github/ISSUE_TEMPLATE/security.md
  • SECURITY.md

Out of scope

  • Setting up a bug bounty program
  • Automating SLA tracking

Metadata

Metadata

Assignees

Labels

GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Stellar WaveIssues in the Stellar wave programdocsDocumentationgood first issueGood for newcomerssecuritySecurity related tasks

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions