Skip to content

Add SECURITY.md with policy for private security reports - #1

Open
dwnoble wants to merge 1 commit into
mainfrom
add-security-policy
Open

Add SECURITY.md with policy for private security reports#1
dwnoble wants to merge 1 commit into
mainfrom
add-security-policy

Conversation

@dwnoble

@dwnoble dwnoble commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

This PR adds a SECURITY.md file directing reporters to submit security vulnerabilities privately to support@datacommons.org, preventing public disclosure of issues.

@dwnoble
dwnoble requested a review from dhotchkiss August 11, 2026 18:56

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a new SECURITY.md file outlining the project's security policy and instructions for reporting vulnerabilities. The reviewer suggested enhancing the policy by adding a response timeline to set clear expectations for security researchers.

Comment thread SECURITY.md

## Reporting a Vulnerability

Please report any security vulnerabilities by emailing us at [support@datacommons.org](mailto:support@datacommons.org). Please do not open a public issue or pull request.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

It is highly recommended to set expectations for security researchers by including a response timeline (e.g., acknowledging the report within 48 hours). This encourages responsible disclosure and establishes clear communication.

Suggested change
Please report any security vulnerabilities by emailing us at [support@datacommons.org](mailto:support@datacommons.org). Please do not open a public issue or pull request.
Please report any security vulnerabilities by emailing us at [support@datacommons.org](mailto:support@datacommons.org). Please do not open a public issue or pull request. We will acknowledge receipt of your report within 48 hours and keep you updated on the progress of our investigation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants