Skip to content

SECURITY.md: decide on disclosure timeline, safe harbour, and a role contact address #331

Description

@gnanirahulnutakki

Surfaced while writing #329. Filing rather than fixing, because these are policy commitments only the maintainer can make — inventing them on the maintainer's behalf would be its own kind of overclaiming.

Current state

SECURITY.md is functional and correct. It has a private reporting channel (GitHub Security Advisory preferred, email fallback), required report fields, and a vulnerability taxonomy well-tailored to the threat model, plus an honest pointer at docs/known-limitations.md.

Gaps

  • No disclosure timeline or response-time expectation. Reporters have no idea whether to expect a reply in 3 days or 3 months.
  • No coordinated-disclosure window or embargo policy.
  • No safe-harbour statement. Good-faith researchers have no written assurance.
  • No PGP key for the email fallback.
  • Contact is a personal address (gnani.nutakki@gmail.com) rather than a role address. Note the repo's own tooling references security@ardur.ai, which appears nowhere in SECURITY.md — worth reconciling either way.

Decision needed

Which of these to adopt. A single-maintainer project committing to a 24h SLA would be worse than saying nothing; a "best effort, expect an ack within N days" line is honest and useful. The safe-harbour statement is probably the highest value-per-word item here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions