Skip to content

add security policy for vulnerability reporting#129

Open
Aaravanand00 wants to merge 1 commit into
hyperledger-identus:mainfrom
Aaravanand00:chore/openssf-improvements
Open

add security policy for vulnerability reporting#129
Aaravanand00 wants to merge 1 commit into
hyperledger-identus:mainfrom
Aaravanand00:chore/openssf-improvements

Conversation

@Aaravanand00
Copy link
Copy Markdown

Summary

This adds a SECURITY.md file to define how security vulnerabilities should be reported.

What changed

  1. added SECURITY.md with supported versions
  2. included link to the Hyperledger security process

Why

This makes it clear how to report vulnerabilities and aligns the repo with basic OpenSSF and scorecard expectations.

Notes

  1. kept the change minimal
  2. existing security-related configs (scorecard, dependabot, etc.) were already in place

Copilot AI review requested due to automatic review settings April 22, 2026 10:23
@Aaravanand00 Aaravanand00 force-pushed the chore/openssf-improvements branch from 4e5cf7a to 35df70b Compare April 22, 2026 10:24
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a repository security policy document to clarify how to report vulnerabilities and which versions are supported, aligning the repo with common OpenSSF/Scorecard expectations.

Changes:

  • Added SECURITY.md describing supported versions.
  • Documented the vulnerability reporting path via the Hyperledger Security Process.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread SECURITY.md Outdated
@Aaravanand00 Aaravanand00 force-pushed the chore/openssf-improvements branch 2 times, most recently from 4b2e0ae to 8cf68bd Compare April 22, 2026 10:33
Signed-off-by: Aaravanand00 <aaravanand5749@gmail.com>
Copilot AI review requested due to automatic review settings April 30, 2026 18:35
@Aaravanand00 Aaravanand00 force-pushed the chore/openssf-improvements branch from 8cf68bd to 6fd2851 Compare April 30, 2026 18:35
@sonarqubecloud
Copy link
Copy Markdown

Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated 1 comment.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread SECURITY.md
Comment on lines +1 to +4
# Security Policy

## Reporting a Vulnerability

Copy link

Copilot AI Apr 30, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR description says SECURITY.md includes “supported versions”, but the file currently only documents the reporting channel. Either add a “Supported Versions” section (as GitHub’s SECURITY.md format expects) or update the PR description to match what’s actually being added.

Copilot uses AI. Check for mistakes.
@Aaravanand00
Copy link
Copy Markdown
Author

Hi @amagyar-iohk Copilot suggested adding a 'Supported Versions' section to the SECURITY.md file to follow GitHub's standard format. Could you please let me know which versions are currently officially supported? Once confirmed, I'll update the file with the correct table...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants