pq-code-package/tsc

Develop a security policy

Opened this issue · 3 comments

Develop a security policy

As part of this

  • a private mailing list will likely be needed (see lists.pqca.org - need to decide project-specific, pqca level, or both)
  • update SECURITY.md across all repos (to point to the authoritative link)

The following templates may be useful in setting this up:

It covers @planetf1 's points and then some.

At the TSC meeting held 2023-05-23 We agreed to

  • Create a SECURITY.md in each repository
  • Enable github private security vulnerability reporting