Skip to content

Add security policy with vulnerability reporting workflow#295

Merged
Alex4SSB merged 7 commits intomasterfrom
copilot/open-vulnerability-draft
Feb 13, 2026
Merged

Add security policy with vulnerability reporting workflow#295
Alex4SSB merged 7 commits intomasterfrom
copilot/open-vulnerability-draft

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Feb 13, 2026

Repository lacked formal security policy following @blankshiro's vulnerability report in #294.

Changes

  • SECURITY.md: Establishes vulnerability reporting workflow

    • Private disclosure via GitHub Security Advisories (preferred)
    • Alternative MITRE CVE submission if GitHub advisory system inaccessible
    • Response SLAs and disclosure process
    • Troubleshooting steps for antivirus-blocked advisory access
    • Hall of Fame crediting security researchers
  • README.md: Links to security policy from main page

  • Attribution: Generated by GitHub Copilot

Security Reporting Flow

Reporter → GitHub Security Advisory (private)
       → Maintainer review → Fix → Publish → Auto CVE
       
Fallback: Direct MITRE submission if GitHub blocked

💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

Copilot AI changed the title [WIP] Accept and open vulnerability report as draft Add security documentation for vulnerability advisory workflow Feb 13, 2026
Copilot AI requested a review from Alex4SSB February 13, 2026 13:07
Copilot AI changed the title Add security documentation for vulnerability advisory workflow Add security policy for vulnerability reporting Feb 13, 2026
Copilot AI changed the title Add security policy for vulnerability reporting Add security policy with vulnerability reporting workflow Feb 13, 2026
@Alex4SSB Alex4SSB marked this pull request as ready for review February 13, 2026 13:17
@Alex4SSB Alex4SSB merged commit a560b5f into master Feb 13, 2026
@Alex4SSB Alex4SSB deleted the copilot/open-vulnerability-draft branch February 13, 2026 13:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants