-
Notifications
You must be signed in to change notification settings - Fork 909
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
(doc) Add security.md file #1902
Conversation
This replaces that current issue template that we have specifically for security related issues. Instead of starting to create a new issue, which is what happens currently, this will simply display the policy to the user.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I like the change. Makes it much clearer. One thought - It may be better to be at the top so people don't just stop at the first one they find that might match (likely raising a normal issue) rather than going through the whole list?
@pauby I actually thought the same. but from what I can see, I don't think we can control that 😢 |
@gep13 I thought we could. I think you can do it by naming the templates so they sit in alphabetical order you need - see https://github.com/chocolatey-community/chocolatey-package-requests/tree/master/.github/ISSUE_TEMPLATE |
@pauby yes, but this file that I just added, sits outside the ISSUE_TEMPLATE folder. It is at the root of the .github folder. |
So, it's not |
@ferventcoder as a side note, we have the often of moving these files (once we are happy with them) to a new |
To be fair, I did not check that 😄 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good to me! Much clearer!
I would also recommend adding a link to the security policy in the README.md (actually, github recommends it), as well as perhaps in the contribution guidelines. |
LGTM! |
This addition, changes the following:
To this:
Which, once you click on it, show the policy, rather than starting to create a new issue:
We might want to expand on the content a little bit. For example, this is what @AdmiringWorm (who I am stealing the idea from) is using:
https://github.com/WormieCorp/.github/blob/master/.github/SECURITY.md
And also another example here:
https://github.com/standard/.github/blob/master/SECURITY.md
Thoughts?