Skip to content

Add SECURITY.md for public vulnerability reporting #12

Description

@TechLuddite

Summary

NetReady has no SECURITY.md. As a public security-adjacent tool (port scanning, DNS probing, network diagnostics), it should provide a clear channel for responsible disclosure.

Details

  • Add a short SECURITY.md with contact email and an expected response window (e.g. ~90 days).
  • Enable private vulnerability reporting in the repo settings if not already on.
  • This is a hygiene gap, not an active vulnerability.

Skill reference

Code-reviews skill: security first; missing SECURITY.md on public repos is a must-fix.


GrokLuddite gen AI on behalf of TechLuddite

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationsecurity

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions