rafiki icon indicating copy to clipboard operation
rafiki copied to clipboard

docs: add a security policy

Open UlisesGascon opened this issue 4 months ago • 1 comments

👋 Hi everyone! We’re @UlisesGascon and @RafaelGSS, working with the OpenJS Foundation as part of the Alpha-Omega initiative. Our focus is supporting OpenJS projects in strengthening their security posture. We can help with things like:

  • Reviewing or creating security documentation (e.g., SECURITY.md, incident response plans...)
  • Supporting vulnerability handling and escalation (reporting, triage, CVEs, disputes)
  • Reviewing repo configurations and GitHub security settings
  • Sharing best practices (e.g., OSSF Scorecard)
  • Answering general questions on licenses, compliance, or incident response

:sparkles: We’re here as a resource for the Webhint team and happy to collaborate on whatever is most useful for you. Looking forward to working together!

References:

  • https://github.com/openjs-foundation/cross-project-council/pull/1588
  • https://openjsf.org/blog/openjs-foundation-cna
  • https://openjsf.org/blog/security-support-for-openjs-projects

Important

The policy suggests that reports should be submitted using the Report a Vulnerability feature. Since this option is currently unavailable, please follow the instructions

UlisesGascon avatar Sep 15 '25 10:09 UlisesGascon

Deploy Preview for brilliant-pasca-3e80ec canceled.

Name Link
Latest commit 896a00ea1fbebcae31e741437cb2ab985201dd3f
Latest deploy log https://app.netlify.com/projects/brilliant-pasca-3e80ec/deploys/68c7ec161de8380008d0b296

netlify[bot] avatar Sep 15 '25 10:09 netlify[bot]