Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

missing Security policy text in bittensor repo #1819

Open
mjurbanski-reef opened this issue Apr 28, 2024 · 0 comments
Open

missing Security policy text in bittensor repo #1819

mjurbanski-reef opened this issue Apr 28, 2024 · 0 comments
Labels
feature new feature added

Comments

@mjurbanski-reef
Copy link
Contributor

Is your feature request related to a problem? Please describe.

When I head to https://github.com/opentensor/bittensor/security , I see no Security policy was set, i.e. I do not know how the project maintainers would like the security bugs to be reported.

Describe the solution you'd like

It is pretty self-explanatory, create a SECURITY.md with a policy.

Examples of policies could be:

  • one clearly saying all bugs can be reported to the issue tracker with some clear text in the title for example
  • one asking users for "responsible disclosure" adding an email to which such security vulnerability report can be set. Such policies should also include a deadline, for example, 30 days, which is basically for how long bittensor team asks the original reporter to postpone public disclosure.
  • one including bug bounty program - this actually incentives well-meaning users to use whatever procedure bittensor team prefers

Describe alternatives you've considered

No response

Additional context

No response

@mjurbanski-reef mjurbanski-reef added the feature new feature added label Apr 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature new feature added
Projects
None yet
Development

No branches or pull requests

1 participant