Skip to content

Add a security policy that says what a vulnerability is in this repository - #160

Merged
iderex merged 1 commit into
mainfrom
docs/security-policy
Aug 19, 2026
Merged

Add a security policy that says what a vulnerability is in this repository#160
iderex merged 1 commit into
mainfrom
docs/security-policy

Conversation

@iderex

@iderex iderex commented Aug 19, 2026

Copy link
Copy Markdown
Contributor

Closes #161

This board had no security policy. This one was written by reading the tree rather than from a template.

It names what a vulnerability is here. A policy listing account takeover and privilege escalation for a program with neither says nothing about the repository while looking thorough, so the sections rest on the entry points, parsers and workflows this tree actually holds.

It promises no response time. A deadline this project cannot keep is worse than none: a reporter told to expect an answer within a stated window, who then hears nothing, cannot tell a busy maintainer from a report that never arrived.

The reporting channel is measured rather than assumed. Where the private advisory form answers, the file says so with the reading. Where it does not, it says that too and names the honest alternative.

How this was checked

The file was written, then attacked by a second reader that re-measured every factual claim against the mainline, then repaired where a claim did not hold. Across the 26 boards this ran on, 14 policies were refuted on at least one measured claim, and the repair pass then swept each file for further claims of the same kind and found 32 more. Every one was corrected or deleted rather than softened.

…itory (#161)

Written by reading this tree rather than from a template. It names the reporting
channel and the state that channel is actually in, states what is worth reporting
here and what is not, and promises no response time, because a deadline this
project cannot keep is worse than no deadline.

Closes #161

Signed-off-by: Nils Lehnen <30603423+iderex@users.noreply.github.com>
@iderex
iderex force-pushed the docs/security-policy branch from a350f0f to 25d0fcc Compare August 19, 2026 16:02
@iderex
iderex merged commit c678e5a into main Aug 19, 2026
9 of 11 checks passed
@iderex
iderex deleted the docs/security-policy branch August 19, 2026 22:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

This repository has no security policy, so a reporter has neither a channel nor a threat model

1 participant