Skip to content

docs: add SECURITY.md with public vulnerability reporting policy - #30

Merged
CakeRepository merged 1 commit into
masterfrom
claude/security-policy
Oct 4, 2026
Merged

CakeRepository merged 1 commit into
masterfrom
claude/security-policy

Conversation

@CakeRepository

Copy link
Copy Markdown
Owner

Summary

Adds a SECURITY.md stating that vulnerabilities are reported publicly through GitHub issues, so anyone can review the report and contribute a fix. This answers requests like #23 up front.

  • Lists what a useful report contains: affected version, impact, reproduction, and an optional fix.
  • Asks reporters to redact real service account tokens, op:// references, and revealed values, and to rotate any token exposed while testing.
  • Says fixes ship in the latest 4.x release only.
  • Says confirmed issues get a patch release, a CHANGELOG Security entry, and a credited GitHub Security Advisory, as with 4.0.2 / GHSA-q3gg-rgxh-gh64.
  • Adds a one-line link from the README's Security & privacy section.

Docs only. SECURITY.md isn't in the package files, so the npm package doesn't change.

Follow-up for the maintainer

GitHub private vulnerability reporting is still enabled on this repo. That shows a "Report a vulnerability" button that contradicts this policy. Turn it off under Settings → Code security → Private vulnerability reporting.

🤖 Generated with Claude Code

Security reports are handled in public GitHub issues so anyone can
review and help fix them. Documents what a useful report contains,
asks reporters to redact real tokens and op:// references, and
describes how confirmed issues are released and credited. Linked from
the README's Security & privacy section.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@CakeRepository
CakeRepository merged commit bdb6625 into master Oct 4, 2026
3 checks passed
@CakeRepository CakeRepository mentioned this pull request Oct 4, 2026
4 of 5 tasks
CakeRepository added a commit that referenced this pull request Oct 4, 2026
Bump version in package.json, package-lock.json, server.json and
SERVER_VERSION, and cut the 4.0.3 CHANGELOG entry covering the
vitest 4.1.11 dev dependency update (#29), the Node 20/22/24 CI
matrix, and SECURITY.md (#30).

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant