Skip to content

Commit 03280c1

Browse files
committed
Add Security section
1 parent 3d1fd85 commit 03280c1

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

docs/terms-policies/governance.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -108,6 +108,20 @@ Path to role:
108108
- Creates a GitHub release for the tag
109109
- For [dandi-cli](https://github.com/dandi/dandi-cli), upon release a new version is published to PyPI
110110

111+
## 9. Security
112+
113+
### 9.1 Reporting
114+
- Security reports via [email protected]
115+
- Acknowledge within 48 hours
116+
117+
### 9.2 Handling
118+
- Initial assessment within 5 business days
119+
- Coordinate and address issue within 30 days
120+
- User advisory via email when appropriate
121+
122+
### 9.3 Hardening Practices
123+
- Mandatory dependency scanning
124+
- Principle of least privilege enforced for service accounts
111125

112126
## 10. Documentation
113127

0 commit comments

Comments
 (0)