🔒️ Add security guidelines for vulnerability disclosure.#51
Merged
JSKitty merged 5 commits intoVectorPrivacy:masterfrom Mar 3, 2026
Merged
🔒️ Add security guidelines for vulnerability disclosure.#51JSKitty merged 5 commits intoVectorPrivacy:masterfrom
JSKitty merged 5 commits intoVectorPrivacy:masterfrom
Conversation
Added a security policy for vulnerability disclosure guidelines. Requires an e-mail address and setting up the Private Security Disclosure system on GitHub.
Removed 'Secure storage of messages' from security considerations. (As Vector doesn't store the messages)
Updated the security contact email to the new domain.
|
Thank you for catching this and filling the gap. As I shared, we had it for the Vector SDK thanks to @Luke-Larsen, but appreciate you spotting this and adding the solution, @selkij! Will have @JSKitty review to make sure everything is up to standard before pushing. |
- Added a compensation section to clarify the project's current stance on financial rewards for disclosures. - Added another e-mail for reporting a vulnerability.
Author
|
Does this look good ? You can tell me directly what to change by using the reviewing GitHub feature. |
Author
|
It can be merged then! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Added a security policy for vulnerability disclosure guidelines. Requires an e-mail address and setting up the Private Security Disclosure system on GitHub.