Skip to content

docs: add security disclosure policy#188

Open
peterxing wants to merge 1 commit into
blacksky-algorithms:mainfrom
peterxing:fix/issue-183-security-policy
Open

docs: add security disclosure policy#188
peterxing wants to merge 1 commit into
blacksky-algorithms:mainfrom
peterxing:fix/issue-183-security-policy

Conversation

@peterxing
Copy link
Copy Markdown

Summary

  • adds a root SECURITY.md so GitHub exposes a clear private reporting path
  • repeats the rudy@blacksky.app security contact already mentioned in CONTRIBUTING.md
  • adds a concise report template, coordinated-disclosure flow, and safe scope guidance for rsky services/crates

Verification

  • git diff --check
  • direct marker check for reporting address, coordinated disclosure, private-reporting wording, and scope guidance

Closes #183.

@peterxing
Copy link
Copy Markdown
Author

I opened this as a narrow responsible-disclosure policy PR using the existing private reporting contact.

If helpful, I can turn it into either:

  • A$390 security-policy readback: supported versions, reporting path, safe harbor, response targets, and rsky-specific scope examples
  • A$690 security-program launch packet: scope matrix, severity/reward rubric, disclosure SLA, triage workflow, advisory template, and announcement copy

Details/proof/payment options: https://0741ec59.farmbot-platform-mvp.pages.dev/hire-agent/

Default payment is USDC on Base or Polygon, or invoice if preferred.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Policy / Responsible Disclosure (seeking clarification)

1 participant