Skip to content

[DOCS] Create SECURITY.md with responsible disclosure policy #1910

@Priyanshu-byte-coder

Description

@Priyanshu-byte-coder

Problem

DevTrack has no SECURITY.md file. GitHub recommends this for all public repositories so security researchers know how to responsibly disclose vulnerabilities.

Task

Create SECURITY.md in the repo root with:

  1. Supported versions (which version of DevTrack is receiving security fixes)
  2. How to report a vulnerability (email or GitHub private vulnerability reporting)
  3. Expected response time
  4. What happens after a report is received

Template to follow

GitHub's official template: https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository

Acceptance criteria

  • SECURITY.md exists at repo root
  • Contains supported versions table
  • Contains clear reporting instructions
  • GitHub shows the security policy in the Security tab

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentationgood first issueGood for newcomersgssoc26GSSoC 2026 contributiongssoc:assignedGSSoC: Issue assigned to a contributorlevel:beginnerGSSoC: Beginner difficulty (20 pts)type:docsGSSoC type bonus: documentation (+5 pts)

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions