Skip to content

Establish private security reporting and review policy - #1

Open
vtino17 wants to merge 1 commit into
mainfrom
agent/security-governance
Open

Establish private security reporting and review policy#1
vtino17 wants to merge 1 commit into
mainfrom
agent/security-governance

Conversation

@vtino17

@vtino17 vtino17 commented Aug 2, 2026

Copy link
Copy Markdown
Owner

Summary

Establish a private vulnerability reporting policy and explicit contribution/review rules for this public repository.

Why

Security reports should not expose undisclosed vulnerabilities in public issues. The new policy links to GitHub private vulnerability reporting, which has been enabled for this repository, and defines the information reporters should provide without including secrets or private infrastructure data. The contribution guide also requires focused changes, regression coverage, documented validation, English PR descriptions, and independent review for security-sensitive work.

Validation

  • All shell scripts parse; relative Markdown links and whitespace validation passed.
  • The private advisory endpoint is enabled for vtino17/network-security-lab.
  • The diff contains documentation/governance changes only.

Independent human review is requested before merge.

@vtino17
vtino17 marked this pull request as ready for review August 2, 2026 10:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant