Skip to content

Add SECURITY.md#12980

Merged
Fenrirthviti merged 1 commit intoobsproject:masterfrom
Fenrirthviti:securitytemplate
Mar 24, 2026
Merged

Add SECURITY.md#12980
Fenrirthviti merged 1 commit intoobsproject:masterfrom
Fenrirthviti:securitytemplate

Conversation

@Fenrirthviti
Copy link
Copy Markdown
Member

Description

Add a SECURITY.md template to the repo that follows what we're actually accepting security requests on. Currently, this only includes RCEs, but may be updated before merge or at a later date to include others.

Motivation and Context

Tired of the low-effort and LLM-generated PRs to try and add one.

How Has This Been Tested?

👁️

Types of changes

  • Documentation (a change to documentation pages)

Checklist:

  • My code has been run through clang-format.
  • I have read the contributing document.
  • My code is not on the master branch.
  • The code has been tested.
  • All commit messages are properly formatted and commits squashed where appropriate.
  • I have included updates to all appropriate documentation.

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md
@Fenrirthviti
Copy link
Copy Markdown
Member Author

Fixed a few other typos, and updated the resolution time to 120 days to more closely align with our release cadence.

@namoen0301
Copy link
Copy Markdown

namoen0301 commented Jan 28, 2026

please add a PGP public key, Some security researchers submit their vulnerability report after encrypting with PGP.

@Fenrirthviti
Copy link
Copy Markdown
Member Author

We can consider adding a PGP key in the future, but we do not have compatible infrastructure (gsuite) for it at the moment.

@Fenrirthviti Fenrirthviti merged commit b8ab531 into obsproject:master Mar 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants