Make WordPress Core

Opened 7 years ago

Closed 7 years ago

Last modified 7 years ago

#48521 closed enhancement (fixed)

Add a Github Security Policy

Reported by: whyisjake Owned by: whyisjake
Priority: normal Milestone: 5.4
Component: Security Version: 5.3
Severity: normal Keywords:
Cc: Focuses:

Description

As part of the work that the Core Security team is undertaking, we should create a Security Policy for Github.

https://help.github.com/en/github/managing-security-vulnerabilities/adding-a-security-policy-to-your-repository

This document will live at the root of wordpress-develop, and will serve as a public-facing document detailing the security policies for core.

Attachments (1)

48521.diff (6.7 KB ) - added by whyisjake 7 years ago.

Download all attachments as: .zip

Change History (8)

@whyisjake
7 years ago

#1 @SergeyBiryukov
7 years ago

  • Component GeneralSecurity

#2 @ayeshrajans
7 years ago

Yay this is nice.
Shouldn't we link to the HackerOne page from the SECURITY.md file? https://hackerone.com/wordpress

This ticket was mentioned in Slack in #core-committers by whyisjake. View the logs.


7 years ago

#4 @whyisjake
7 years ago

  • Owner set to whyisjake
  • Resolutionfixed
  • Status assignedclosed

In 46735:

Security: Add a GitHub Security Policy.

As part of more responsible security disclosure, we are adding a security policy to GitHub.

Fixes #48521.
Props whyisjake, ayeshrajans.

#5 @ayeshrajans
7 years ago

#47368 was marked as a duplicate.

#6 @SergeyBiryukov
7 years ago

In 46736:

Security: Add WordPress 5.3.x to the "Supported Versions" section of GitHub Security Policy.

Props imath.
Fixes #48667. See #48521.

#7 @SergeyBiryukov
7 years ago

In 47403:

Tests: Add a unit test to ensure the "Supported Versions" section of GitHub Security Policy always includes the latest stable branch.

See #48667, #48521.

Note: See TracTickets for help on using tickets.