rafiki
rafiki copied to clipboard
docs: add a security policy
👋 Hi everyone! We’re @UlisesGascon and @RafaelGSS, working with the OpenJS Foundation as part of the Alpha-Omega initiative. Our focus is supporting OpenJS projects in strengthening their security posture. We can help with things like:
- Reviewing or creating security documentation (e.g., SECURITY.md, incident response plans...)
- Supporting vulnerability handling and escalation (reporting, triage, CVEs, disputes)
- Reviewing repo configurations and GitHub security settings
- Sharing best practices (e.g., OSSF Scorecard)
- Answering general questions on licenses, compliance, or incident response
:sparkles: We’re here as a resource for the Webhint team and happy to collaborate on whatever is most useful for you. Looking forward to working together!
References:
- https://github.com/openjs-foundation/cross-project-council/pull/1588
- https://openjsf.org/blog/openjs-foundation-cna
- https://openjsf.org/blog/security-support-for-openjs-projects
Important
The policy suggests that reports should be submitted using the Report a Vulnerability feature. Since this option is currently unavailable, please follow the instructions
Deploy Preview for brilliant-pasca-3e80ec canceled.
| Name | Link |
|---|---|
| Latest commit | 896a00ea1fbebcae31e741437cb2ab985201dd3f |
| Latest deploy log | https://app.netlify.com/projects/brilliant-pasca-3e80ec/deploys/68c7ec161de8380008d0b296 |