Skip to content

VBC-931: missing-security-policy

warning

Category: git
Analysis: Git
Tags: git security project-health

What it reports

Missing SECURITY.md file. Without a security disclosure policy, researchers who find vulnerabilities in your project have no private channel to report them and may resort to public disclosure. Add a SECURITY.md with a contact email and responsible disclosure policy.

Examples

Exercised by git-checker.test.ts: needs a repository working tree.

Released under the MIT License.