Skip to content

Add default security disclosure and support guidance #7

Description

@Scriptception

Problem

The organization profile does not provide inherited SECURITY or SUPPORT files, so users may disclose vulnerabilities publicly or open product defects through an unsuitable contact path.

User outcome

Users can route sensitive reports and ordinary help requests safely to the accountable maintainers.

Scope

  • Add an inherited SECURITY policy with supported-version and disclosure-routing placeholders that remain publication-safe.
  • Add SUPPORT guidance distinguishing defects, usage questions, and sensitive reports.
  • Document repository-specific override requirements.
  • Link both paths from the profile and default issue configuration.

Non-goals

  • Publishing credentials, internal contacts, or response details that cannot be maintained.
  • Promising one support level for every product.

Acceptance criteria

  • Public repositories without overrides show usable disclosure and support instructions.
  • Sensitive reports are explicitly kept out of public issues.
  • Each file names ownership and review cadence.
  • Repositories with a different support model can override cleanly.

Validation

  • Inspect inherited community health files on a repository without local equivalents.
  • Walk through defect, usage-question, and vulnerability-report scenarios.

Relationships

  • Feeds default issue-form configuration.
  • Complements product-specific security policies.

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions