-
Notifications
You must be signed in to change notification settings - Fork 122
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Suggestion to Relocate Security Policy to Root Folder for XZ Project #148
Comments
This issue made me realize that I hadn't included a Reporting bugs section on the home page. I have fixed this in XZ Utils, XZ for Java, and XZ Embedded pages now. While this wasn't the point of your report, thanks for making me notice it still. :-) I added a default SECURITY.md to this organization (I only learned of this feature today). Now XZ Embedded and XZ for Java have vulnerability reporting information visible on GitHub in addition to the information being on the home pages of those projects. XZ Utils has its own SECURITY.md still. I'm tempted to remove it and let GitHub show the default file instead. It's simpler if this kind of information needs to be maintained in fewer places. For example, with long-term branches (like I hadn't heard about Scorecard before. Thanks for linking to the relevant documentation. I looked at the report about xz (generated at 2024-11-18).
I'm not interested in doing something solely because it looks good in some statistics. It should already be easy enough to figure out how to report security bugs in this project. Now that I have read a bit more about Scorecard, I feel even more tempted to remove XZ Utils' SECURITY.md. Don't take me wrong, Scorecard gives useful advice but following it solely to improve the scores doesn't add any real value. I'm still open to listening different viewpoints before I proceed with SECURITY.md. Thanks! |
Now that there is the organization-wide SECURITY.md, Scorecard seems to find that file and give the score of 10 on Security-Policy. Thus, it seems there's no need for SECURITY.md in the xz.git repository at all to get a good score in the Scorecard game.
|
The Security Policy for this project is currently located in the
.github
directory (xz/.github/SECURITY.md
). The scorecard tool is unable to detect it because it is not in the root folder.Proposed Action:
Move the
SECURITY.md
file fromxz/.github/
to the root directoryxz/
.References:
Scorecard documentation: Link to Scorecard Checks
Thank you for your time and consideration!
The text was updated successfully, but these errors were encountered: