Add a security policy that says what a vulnerability is in this repository - #160
Merged
Conversation
…itory (#161) Written by reading this tree rather than from a template. It names the reporting channel and the state that channel is actually in, states what is worth reporting here and what is not, and promises no response time, because a deadline this project cannot keep is worse than no deadline. Closes #161 Signed-off-by: Nils Lehnen <30603423+iderex@users.noreply.github.com>
iderex
force-pushed
the
docs/security-policy
branch
from
August 19, 2026 16:02
a350f0f to
25d0fcc
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #161
This board had no security policy. This one was written by reading the tree rather than from a template.
It names what a vulnerability is here. A policy listing account takeover and privilege escalation for a program with neither says nothing about the repository while looking thorough, so the sections rest on the entry points, parsers and workflows this tree actually holds.
It promises no response time. A deadline this project cannot keep is worse than none: a reporter told to expect an answer within a stated window, who then hears nothing, cannot tell a busy maintainer from a report that never arrived.
The reporting channel is measured rather than assumed. Where the private advisory form answers, the file says so with the reading. Where it does not, it says that too and names the honest alternative.
How this was checked
The file was written, then attacked by a second reader that re-measured every factual claim against the mainline, then repaired where a claim did not hold. Across the 26 boards this ran on, 14 policies were refuted on at least one measured claim, and the repair pass then swept each file for further claims of the same kind and found 32 more. Every one was corrected or deleted rather than softened.