Skip to content

[Enhancement] Add SECURITY.md as org default #9

Description

@CTristan

Summary

Add SECURITY.md at the repo root. GitHub surfaces this org-wide as the default security policy for repos without their own.

Why

Community health file expected by GitHub. Gives security reporters a clear, non-public channel before the org goes public.

Acceptance Criteria

  • SECURITY.md exists at repo root
  • Describes supported versions (or states the org's position if N/A)
  • Provides a private reporting channel (e.g., GitHub private vulnerability reporting enabled, or a dedicated email)
  • Sets expectations for response time
  • GitHub's community health UI picks it up as the org default

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions