Skip to content

Add more rejected examples in SECURITY.md - #23608

Open
alexandre-daubois wants to merge 1 commit into
php:masterfrom
alexandre-daubois:security-md-improvements
Open

Add more rejected examples in SECURITY.md#23608
alexandre-daubois wants to merge 1 commit into
php:masterfrom
alexandre-daubois:security-md-improvements

Conversation

@alexandre-daubois

Copy link
Copy Markdown
Member

Some teach backs from the last couple months of advisories triage. We hope that it'll help improve LLM generated reports we get (safe to say all the reports we get) and mitigate a lot of false positives.

@LamentXU123 LamentXU123 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's a nice addition!

@iluuu1994 iluuu1994 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md
or a non-default allocator, starting with `USE_ZEND_ALLOC=0`, which also
drops the `memory_limit` check.

# Writing a Report We Can Act On

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm a bit unsure about this document diverging more and more from https://github.com/php/policies/blob/main/security-classification.rst. Originally we just copied a few section and reworded them, because we were hoping LLM tools would read them.

@alexandre-daubois alexandre-daubois Sep 7, 2026

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If you think that make more sense, I'd be fine creating a PR in php/policies to add this part there instead

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants