Repository documents how to report a vulnerability
docs/security-policy@v1
The repository has a SECURITY.md saying where to report a security problem.
| Id | docs/security-policy |
| Version | v1 |
| Category | docs |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | files |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
files | Presence, size and line counts of the well known files a repository is expected to carry, plus any extra path the guardrail asks for. | path |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "docs/security-policy@v1",
"severity": "warning",
"with": {
"path": "SECURITY.md",
"minLines": "3",
"contact": "true"
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
path | Path to the security policy, relative to the directory the CLI runs in. | SECURITY.md | GUARDRAIL_INPUT_PATH |
minLines | How many non-blank lines it needs before it counts as written. | 3 | GUARDRAIL_INPUT_MINLINES |
contact | Whether the policy must include a way to get in touch, either an email address or a URL. | true | GUARDRAIL_INPUT_CONTACT |
How to fix
Add a SECURITY.md at the repository root, or under .github/, saying where to report a vulnerability and how quickly a reporter can expect a response:
# Security
Report a vulnerability to security@company.com. We acknowledge within two working days.GitHub links this file from the repository's Security tab and from the advisory form. Without it, a researcher who finds something has nowhere to send it except a public issue, and that is a disclosure, not a report.
More in docs
docs/agent-instructions. The repository has an instruction file for coding agents, long enough to say something and short enough to be read in full.docs/changelog. The repository has a changelog, so what changed between two releases is written down instead of pieced together from commits.docs/code-of-conduct. The repository has aCODE_OF_CONDUCT.md, so the standard contributors are held to, and who enforces it, is written down.docs/contributing. The repository has aCONTRIBUTING.mdexplaining how a change is proposed, built and reviewed.docs/license-present. The repository has a licence file, so what people may do with the code is written down, not assumed.docs/readme. The repository has a README that says more than just its title.