Security Policy #5705

Closed
opened 2025-12-29 19:31:39 +01:00 by adam · 4 comments
Owner

Originally created by @reedy on GitHub (Nov 23, 2021).

Change Type

Addition

Area

Other

Proposed Changes

Is it possible to get a security policy added to the repo please? As it's unclear how/where security issues should be reported.

https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository

Thanks!

Originally created by @reedy on GitHub (Nov 23, 2021). ### Change Type Addition ### Area Other ### Proposed Changes Is it possible to get a security policy added to the repo please? As it's unclear how/where security issues should be reported. https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository Thanks!
adam added the type: documentation label 2025-12-29 19:31:39 +01:00
adam closed this issue 2025-12-29 19:31:39 +01:00
Author
Owner

@jeremystretch commented on GitHub (Nov 23, 2021):

Please use the bug report form here.

@jeremystretch commented on GitHub (Nov 23, 2021): Please use the bug report form [here](https://github.com/netbox-community/netbox/issues/new?assignees=&labels=type%3A+bug&template=bug_report.yaml).
Author
Owner

@reedy commented on GitHub (Nov 23, 2021):

Thanks. But can we get it actually documented in the repo?

And do you actually want security bugs reporting in public?

@reedy commented on GitHub (Nov 23, 2021): Thanks. But can we get it actually documented in the repo? And do you actually want security bugs reporting in public?
Author
Owner

@kkthxbye-code commented on GitHub (Nov 24, 2021):

@reedy - Please read the non-edit part here:

https://github.com/netbox-community/netbox/issues/7280#issuecomment-920846983

Security issues are normally just posted as public issues yes. Unless it's unauthenticated RCE or something of similar impact, it should be fine to raise as an issue.

@jeremystretch - Maybe it would be fine to create a security.md file, just to point people at the bug report template.

@kkthxbye-code commented on GitHub (Nov 24, 2021): @reedy - Please read the non-edit part here: https://github.com/netbox-community/netbox/issues/7280#issuecomment-920846983 Security issues are normally just posted as public issues yes. Unless it's unauthenticated RCE or something of similar impact, it should be fine to raise as an issue. @jeremystretch - Maybe it would be fine to create a security.md file, just to point people at the bug report template.
Author
Owner

@reedy commented on GitHub (Nov 24, 2021):

Thanks. Most projects (even FOSS-y ones) don't operate that way (and that's fine), so I'm not used to that (even though I'm mostly used to working in the open).

I would concur that a SECURITY.md that does literally just say to use the bug report form would be valuable.

@reedy commented on GitHub (Nov 24, 2021): Thanks. Most projects (even FOSS-y ones) don't operate that way (and that's fine), so I'm not used to that (even though I'm mostly used to working in the open). I would concur that a SECURITY.md that does literally just say to use the bug report form would be valuable.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/netbox#5705