mirror of
https://github.com/nlohmann/json.git
synced 2026-09-26 12:05:48 +00:00
Document response times, supported versions, access, secrets, and dependency policies (#5580)
Answer the OpenSSF Best Practices criteria that asked for policies the project follows but had not written down: - SECURITY.md: a first response within 14 days, publishing an advisory with credit once a fix is released, and that only the latest release receives security fixes. - Governance: who has access to the project's resources, how write or admin access is granted, and how CI secrets are stored and rotated. - Quality assurance: how dependencies of the build, test, and documentation tooling are pinned, scanned, and kept free of known vulnerabilities. Also update the assurance case, since comparison no longer recurses per nesting level (#5390), and point the best practices badge and links to bestpractices.dev under the program's current name. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
17
.github/SECURITY.md
vendored
17
.github/SECURITY.md
vendored
@@ -9,12 +9,23 @@ identified a security vulnerability in this repository, please use the GitHub Se
|
||||
Until it is published, this draft security advisory will only be visible to the maintainers of this project. Other
|
||||
users and teams may be added once the advisory is created.
|
||||
|
||||
We will send a response indicating the next steps in handling your report. After the initial reply to your report, we
|
||||
will keep you informed of the progress towards a fix and full announcement and may ask for additional information or
|
||||
guidance.
|
||||
We will send a first response within 14 days, indicating the next steps in handling your report. After the initial
|
||||
reply to your report, we will keep you informed of the progress towards a fix and full announcement and may ask for
|
||||
additional information or guidance.
|
||||
|
||||
For vulnerabilities in third-party dependencies or modules, please report them directly to the respective maintainers.
|
||||
|
||||
## Disclosure and credit
|
||||
|
||||
Once a fix is released, we publish the security advisory and list the fixed vulnerability in the release notes. We
|
||||
credit the reporter in both, unless they ask not to be named.
|
||||
|
||||
## Supported versions
|
||||
|
||||
Security fixes are made on the `develop` branch and shipped with the next release. Only the latest release receives
|
||||
security fixes; they are not backported to older releases. A release stops receiving security fixes when the next
|
||||
release is published, so please update to the latest release to get them.
|
||||
|
||||
## Unofficial packages
|
||||
|
||||
This project does not publish an official npm package. The npm package
|
||||
|
||||
Reference in New Issue
Block a user