Skip to content

๐ŸŸ [P1] fix(docs): missing SECURITY.md โ€” no vulnerability disclosure policyย #75

Description

@teddylee777

์ปจํ…์ŠคํŠธ ๋ธ”๋ก

Key Value
Category documentation
Checklist ISS-DOC-02 โ€” Missing SECURITY.md with vulnerability disclosure policy
Priority P1 ๐ŸŸ 
Scan Date 2026-04-16
Flagged By @doc-explorer

์š”์•ฝ

  • WHAT: ์ €์žฅ์†Œ ๋ฃจํŠธ ๋˜๋Š” .github/์— SECURITY.md ํŒŒ์ผ ์—†์Œ โ€” ์™ธ๋ถ€ ์—ฐ๊ตฌ์ž๊ฐ€ ์ทจ์•ฝ์ ์„ ๋ฐœ๊ฒฌํ–ˆ์„ ๋•Œ ๋น„๊ณต๊ฐœ๋กœ ๋ณด๊ณ ํ•  ๊ฒฝ๋กœ๊ฐ€ ์ •์˜๋˜์ง€ ์•Š์Œ
  • WHY: GitHub Security Advisories ๊ธฐ๋Šฅ ํ™œ์„ฑํ™” ๋ฐ PGP/์ด๋ฉ”์ผ ์—ฐ๋ฝ์ฒ˜ ์ œ๊ณต์ด OSS ๋ณด์•ˆ์˜ ํ‘œ์ค€. NextAuth + 5 auth ๋ชจ๋“œ๋กœ ๋ณด์•ˆ ๋…ธ์ถœ๋ฉด์ด ๋„“์€ ํ”„๋กœ์ ํŠธ์—๋Š” ํ•„์ˆ˜
  • WHERE: ์ €์žฅ์†Œ ๋ฃจํŠธ (์‹ ๊ทœ ํŒŒ์ผ ์ƒ์„ฑ ํ•„์š”)
  • SEVERITY: HIGH โ€” ์ฑ…์ž„ ๊ณต์‹œ ์ฑ„๋„ ๋ถ€์žฌ๋Š” ์ œ๋กœ๋ฐ์ด ๊ณต๊ฐœ ๋…ธ์ถœ ์œ„ํ—˜

Evidence

# File Line Finding Flagged By Confidence
1 SECURITY.md โ€” ๋ฃจํŠธ ๋””๋ ‰ํ† ๋ฆฌ์— ํŒŒ์ผ ์—†์Œ @doc-explorer High
2 .github/SECURITY.md โ€” .github/ ๋””๋ ‰ํ† ๋ฆฌ์—๋„ ์—†์Œ @doc-explorer High
3 ๊ธฐ์กด ์ด์Šˆ ํŠธ๋ž˜์ปค โ€” ๊ธฐ์กด์— ๋ณด๊ณ ๋œ ์ทจ์•ฝ์ (#57, #58, #59, #64)์€ ๋ชจ๋‘ public ์ด์Šˆ๋กœ ๊ณต๊ฐœ โ€” ๋น„๊ณต๊ฐœ ๊ฒฝ๋กœ๊ฐ€ ์—†์–ด ๊ณต๊ฐœ ์™ธ ์„ ํƒ์ง€๊ฐ€ ์—†์Œ @doc-explorer Medium

์˜ํ–ฅ ๋ถ„์„

์˜ํ–ฅ ๋ฒ”์œ„

  • ์™ธ๋ถ€ ๋ณด์•ˆ ์—ฐ๊ตฌ์ž, Bug Bounty ํ”Œ๋žซํผ ์‚ฌ์šฉ์ž
  • ๊ณต์‹ ์ถœ์‹œ(v1.0) ์ „ ๊ฐ์‚ฌ(audit) ํ”„๋กœ์„ธ์Šค
  • ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ ์ฑ„ํƒ ๊ฒ€ํ†  ์‹œ ๋ณด์•ˆ ์„ฑ์ˆ™๋„ ํ‰๊ฐ€ ํ•ญ๋ชฉ

์žฅ์•  ์‹œ๋‚˜๋ฆฌ์˜ค

  1. ๋ณด์•ˆ ์—ฐ๊ตฌ์ž๊ฐ€ ์‹ฌ๊ฐํ•œ ์ทจ์•ฝ์ (์˜ˆ: RCE, ์ธ์ฆ ์šฐํšŒ) ๋ฐœ๊ฒฌ
  2. ๋น„๊ณต๊ฐœ ๋ณด๊ณ  ๊ฒฝ๋กœ ์—†์Œ โ†’ public ์ด์Šˆ๋กœ ๊ณต๊ฐœ (์ œ๋กœ๋ฐ์ด)
  3. ํŒจ์น˜ ๋ฐฐํฌ ์ „์— ์‹ค์ œ ๊ณต๊ฒฉ ๋ฐœ์ƒ, ์‚ฌ์šฉ์ž ํ”ผํ•ด
  4. ์ฑ…์ž„ ๊ณต์‹œ(responsible disclosure) ์ „ํ†ต ๋ฏธ์ค€์ˆ˜๋กœ OSS ์ปค๋ฎค๋‹ˆํ‹ฐ ์‹ ๋ขฐ ํ•˜๋ฝ

๊ธด๊ธ‰๋„

  • ํ˜„ ์‹œ์  ์‹ฌ๊ฐ ์ทจ์•ฝ์  ์ œ๋ณด ๊ฐ€๋Šฅ์„ฑ์ด ์กด์žฌํ•˜๋Š” ํ•œ ํ•ญ์ƒ ๋ฆฌ์Šคํฌ
  • ๊ธฐ์กด ๋ณด์•ˆ ์ด์Šˆ(๐ŸŸ [P1] fix(security): SSRF prevention incomplete โ€” admin URL bypass and IPv6 gapย #57-64)๊ฐ€ 9๊ฑด โ€” ๋ณด์•ˆ ๋…ธ์ถœ๋ฉด์ด ์‹ค์ œ๋กœ ์žˆ์Œ์ด ํ™•์ธ๋จ

์ œ์•ˆ ํ•ด๊ฒฐ ๋ฐฉ์•ˆ

์ ‘๊ทผ ๋ฐฉ๋ฒ•

์ €์žฅ์†Œ ๋ฃจํŠธ ๋˜๋Š” .github/์— SECURITY.md ์ƒ์„ฑ. ์ตœ์†Œ ํฌํ•จ ํ•ญ๋ชฉ:

# Security Policy

## Supported Versions

| Version | Supported |
| ------- | --------- |
| 1.x     | โœ…        |
| < 1.0   | โŒ        |

## Reporting a Vulnerability

**Please do NOT create a public GitHub issue for security vulnerabilities.**

To report a vulnerability privately:

1. **GitHub Security Advisories (preferred)**: Use the [Security tab](https://github.com/teddynote-lab/langgraph-chat-ui/security/advisories/new) to open a private advisory.
2. **Email**: Send details to `security@brain-crew.com` (PGP key available on request).

We will acknowledge receipt within 3 business days and aim to provide an initial assessment within 7 days.

## Disclosure Policy

- We follow a 90-day coordinated disclosure timeline.
- Credit will be given to reporters in release notes unless anonymity is requested.
- We do not operate a formal bug bounty program at this time.

## Scope

In scope:
- All code in this repository
- Default Docker images published by this project
- Reference configurations in `examples/`

Out of scope:
- Self-modified forks
- Third-party dependencies (report to upstream)
- Infrastructure of individual deployments

GitHub Security Advisories ๊ธฐ๋Šฅ๋„ ์ €์žฅ์†Œ ์„ค์ •์—์„œ ํ™œ์„ฑํ™” (Settings โ†’ Security).

๋Œ€์•ˆ

  • README ๋ณด์•ˆ ์„น์…˜๋งŒ ๋ณด๊ฐ•: README.md์— ๋ณด๊ณ  ๊ฒฝ๋กœ ์ถ”๊ฐ€ โ†’ GitHub UI๊ฐ€ SECURITY.md ์žˆ์„ ๋•Œ ์ž๋™ linking์„ ์ˆ˜ํ–‰ํ•˜๋ฏ€๋กœ ๋ณ„๋„ ํŒŒ์ผ์ด ์šฐ์ˆ˜
  • bug bounty ํ”Œ๋žซํผ ์ด์šฉ: HackerOne/Huntr ๋“ฑ๋ก โ†’ ์œ ๋ฃŒ, OSS ํ”„๋กœ์ ํŠธ ๊ทœ๋ชจ์— ๊ณผ์ž‰

์ˆ˜์šฉ ๊ธฐ์ค€

  • SECURITY.md (๋˜๋Š” .github/SECURITY.md) ์ƒ์„ฑ ๋ฐ ์ปค๋ฐ‹
  • ์ €์žฅ์†Œ Settings โ†’ Security โ†’ Private vulnerability reporting ํ™œ์„ฑํ™”
  • README์— SECURITY.md๋กœ์˜ ๋งํฌ ์ถ”๊ฐ€ ("## Security" ์„น์…˜)
  • ํ•œ๊ตญ์–ด ๋ฒˆ์—ญ ๋ฒ„์ „(SECURITY.ko.md) โ€” ์„ ํƒ์ด์ง€๋งŒ bilingual ํ”„๋กœ์ ํŠธ ๊ด€๋ก€ ์œ ์ง€
  • ํ…Œ์ŠคํŠธ ์ปค๋งจ๋“œ: GitHub UI์—์„œ "Report a vulnerability" ๋ฒ„ํŠผ ๋…ธ์ถœ ํ™•์ธ

์ฐธ์กฐ

์žฌํ˜„ ๋ฐฉ๋ฒ•

์‚ฌ์ „ ์กฐ๊ฑด

  • ๊ณต๊ฐœ ์ €์žฅ์†Œ ๋ฐฉ๋ฌธ

๋‹จ๊ณ„

  1. GitHub ์ €์žฅ์†Œ ๋ฐฉ๋ฌธ
  2. Security ํƒญ ํ™•์ธ
  3. "Report a vulnerability" ๋งํฌ ํ™•์ธ

๊ธฐ๋Œ€ ๊ฒฐ๊ณผ

Private vulnerability reporting ํ™œ์„ฑํ™” ๋ฉ”์‹œ์ง€์™€ ํ•จ๊ป˜ ํผ ๋…ธ์ถœ

์‹ค์ œ ๊ฒฐ๊ณผ

"Security policy not found" ๋˜๋Š” ๊ธฐ๋Šฅ ๋น„ํ™œ์„ฑํ™” ์ƒํƒœ

๊ด€๋ จ ์ฝ”๋“œ ์ปจํ…์ŠคํŠธ

File Role Relevance
SECURITY.md ๋ณด์•ˆ ์ •์ฑ… (์‹ ๊ทœ) ์ƒ์„ฑ ๋Œ€์ƒ
README.md ํ”„๋กœ์ ํŠธ ์—”ํŠธ๋ฆฌ ๋ฌธ์„œ Security ์„น์…˜ ๋งํฌ ์ถ”๊ฐ€
docs/00-OVERVIEW.md ์ „์ฒด ๊ฐœ์š” ๋ณด์•ˆ ์ฐธ์กฐ ์ถ”๊ฐ€ ๊ฒ€ํ† 

Detected by oh-my-braincrew `omb:issue` scan
Category: documentation | Scan date: 2026-04-16
`omb-issue-scan category=documentation checklist=ISS-DOC-02`

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions