Skip to content

Commit

Permalink
Merge pull request #17 from wlandau/56
Browse files Browse the repository at this point in the history
Add security policy
  • Loading branch information
wlandau committed Jun 24, 2024
2 parents d2a732a + 5b941d4 commit 9c4dcac
Show file tree
Hide file tree
Showing 2 changed files with 27 additions and 0 deletions.
1 change: 1 addition & 0 deletions _quarto.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@ website:
menu:
- review.qmd
- conduct.qmd
- security.qmd
tools:
- icon: github
aria-label: "GitHub"
Expand Down
26 changes: 26 additions & 0 deletions security.qmd
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
---
title: "Security Policy"
---

Security threats and vulnerabilities affect everyone using R-multiverse. Issues may include (but are not limited to):

* Unauthorized access to <https://github.com/r-multiverse> or its repositories.
* Malicious attempts to inundate <https://github.com/r-multiverse/contributions/pulls> with pull requests.
* Other [denial of service (DoS) attacks](https://en.wikipedia.org/wiki/Denial-of-service_attack) on the [R-multiverse bot](https://github.com/apps/r-multiverse) or other infrastructure.

Please help keep R-multiverse operational.
In the event of publicly visible malicious behavior, such as a [DoS attack](https://en.wikipedia.org/wiki/Denial-of-service_attack) on <https://github.com/r-multiverse/contributions/pulls>, please:

1. [Report abuse or spam](https://docs.github.com/en/communities/maintaining-your-safety-on-github/reporting-abuse-or-spam) through GitHub.
2. Open an issue at <https://github.com/r-multiverse/help> to inform R-multiverse administrators.

If you notice a vulnerability that an attacker could potentially exploit, please [report it privately](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability).
Confidentiality helps fix the problem before most attackers even know about it.
After remediation, R-multiverse administrators will open an issue at <https://github.com/r-multiverse/help> to inform community about the vulnerability and its resolution.

The steps to [privately report vulnerabilities](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability) are:

1. Navigate to <https://github.com/r-multiverse/help/security>.
2. Under "Private vulnerability reporting", click "Report a vulnerability".
3. Describe the issue in the advisory details form.
4. At the bottom, click "Submit report". GitHub will then add you as a collaborator on the proposed security advisory you created.

0 comments on commit 9c4dcac

Please sign in to comment.