Skip to content

Add a security policy - #135

Open
MichaelLeeHobbs wants to merge 1 commit into
innolitics:masterfrom
MichaelLeeHobbs:add-security-policy
Open

Add a security policy#135
MichaelLeeHobbs wants to merge 1 commit into
innolitics:masterfrom
MichaelLeeHobbs:add-security-policy

Conversation

@MichaelLeeHobbs

Copy link
Copy Markdown

Follows #133. There was no documented channel for security reports; private vulnerability reporting is now enabled, so this writes it down.

The substantive part is the scope section. This repository publishes the data, but the File Editor at dicom.innolitics.com sends its bug reports here, so it isn't obvious to a reporter whether the hosted browser is in scope or where a given problem belongs. The file says so explicitly, and marks faithfully-parsed-but-wrong values as ordinary issues rather than security ones.

Adding SECURITY.md also makes GitHub surface a "Report a vulnerability" link in the issue chooser at /issues/new/choose, which is exactly where the File Editor's "open an issue" link already points.

It also asks reporters not to test against the live site, and notes that the published bundles ship source maps so the browser can be checked offline instead.

One file, no code changes. Happy to reword any of it, particularly the scope section if I've drawn the boundary in the wrong place.

Point vulnerability reports at GitHub's private reporting rather than the
public issue tracker, and state that the hosted DICOM Standard Browser is in
scope alongside this repository. The File Editor already directs its bug
reports here, so the distinction was not obvious to reporters.

Adding this file also makes GitHub surface a "Report a vulnerability" link in
the issue chooser at /issues/new/choose.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant