Repository documents how to report a vulnerability
docs/security-policy@v1
The repository carries a SECURITY.md naming where a security problem should be reported.
| Id | docs/security-policy |
| Version | v1 |
| Category | docs |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | files |
Collectors
This guardrail gathers nothing itself. It depends on the collectors below, which the CLI runs once per build before any check, and reads what they found out of GUARDRAIL_FACTS. A collector that collects nothing skips this guardrail rather than failing it.
| Collector | Gathers | Inputs it is given |
|---|---|---|
files | Presence, size and line counts of the well known files a repository is expected to carry, plus any extra path the guardrail asks for. | path |
The inputs above are this guardrail's own, passed straight through. Configuring one in buildnote.json changes what is collected, and two guardrails configured the same way share the one collection.
Configuration
{
"guardrails": {
"failOn": "error",
"comment": true,
"checks": [
{
"use": "docs/security-policy@v1",
"severity": "warning",
"with": {
"path": "SECURITY.md",
"minLines": "3",
"contact": "true"
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
path | Path to the security policy, relative to the directory the CLI runs in. | SECURITY.md | GUARDRAIL_INPUT_PATH |
minLines | How many non-blank lines it must have before it counts as written. | 3 | GUARDRAIL_INPUT_MINLINES |
contact | Whether the policy must name a way to make contact, an email address or a URL. | true | GUARDRAIL_INPUT_CONTACT |
How to fix
Add a SECURITY.md at the repository root, or under .github/, saying where to report a vulnerability and how quickly a reporter can expect an answer:
# Security
Report a vulnerability to security@acme.com. We acknowledge within two working days.GitHub links this file from the repository's Security tab and from the advisory form. Without it a researcher who finds something has nowhere to send it but a public issue, which is disclosure rather than a report.
More in docs
docs/agent-instructions. The repository carries an agent instruction file, and it is long enough to say something and short enough to be read.docs/changelog. The repository carries a changelog, so what changed between two releases is written down rather than reconstructed from commits.docs/code-of-conduct. The repository carries aCODE_OF_CONDUCT.md, so the standard contributors are held to is written down and so is who enforces it.docs/contributing. The repository carries aCONTRIBUTING.mdsaying how a change is proposed, built and reviewed.docs/license-present. The repository carries a licence file, so what may be done with the code is written down rather than assumed.docs/readme. The repository has a README, and it says more than its title.