slsa-github-generator
slsa-github-generator copied to clipboard
[feature] Add a security policy file
trafficstars
I'm not sure this should be handled via an OSSF-org policy or if individual projects needs their own.
@david-a-wheeler can you advise?
Related #547
Shall we close this issue then?
We should have a SECURITY.md that at least points to the Open-SSF policy I think.
The security policy should also identify the "security team" of members that are knowledgeable about security and will address security issues in order to better comply with OpenSSF security best practices.