Security Policy violation SECURITY.md

Open Beginner friendly
#393 639 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
65/100
Issue type
Documentation
Clarity
Mostly clear
Activity status
Active

Research direction

Start by reviewing the repository's existing contribution and support guidance, then use the linked GitHub security policy documentation to determine the required SECURITY.md contents. Add a SECURITY.md file explaining how to report vulnerabilities securely, enable the repository security policy, and confirm the Allstar issue auto-resolves when the policy is compliant.

Written by the indexing model from the issue text.

Description

allstar

This issue was automatically created by Allstar.

Security Policy Violation
Security policy not enabled.
A SECURITY.md file can give users information about what constitutes a vulnerability and how to report one securely so that information about a bug is not publicly visible. Examples of secure reporting methods include using an issue tracker with private issue support, or encrypted email with a published key.

To fix this, add a SECURITY.md file that explains how to handle vulnerabilities found in your repository. Go to https://github.com/GoogleContainerTools/container-structure-test/security/policy to enable.

For more information, see https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository.


This issue will auto resolve when the policy is in compliance.

Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.

Dominant language
Go
Stars
2.5k
Forks
212
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from GoogleContainerTools/container-structure-test

All issues in GoogleContainerTools/container-structure-test

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.