Skip to content

Factor whether or not private vulnerability reporting is enabled into the scorecard #2465

Description

@JasonKeirstead

Github has finally added the ability for repository owners to turn on private vulnerability reporting, to make disclosing vulnerabilities in a secure manner easier for all parties involved.

https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability

The option is not enabled by default right now.

I believe having this enabled should be considered a best practice and factored into the scorecard.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Status
    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions