Skip to content

docs: add a security policy and disclosure process - #6

Merged
routeplane-ops merged 1 commit into
mainfrom
docs/security-policy
Aug 6, 2026
Merged

docs: add a security policy and disclosure process#6
routeplane-ops merged 1 commit into
mainfrom
docs/security-policy

Conversation

@routeplane-ops

Copy link
Copy Markdown
Collaborator

Adds a documented private-disclosure route. This repo had none, so a researcher who found something had no way to report it privately and no idea what response to expect — for a security product that is a real gap, not a paperwork one.

Mirrors the process already published in routeplane-ce — 72-hour acknowledgement, 7-day assessment, 90-day coordinated disclosure, and an explicit "we do not run a paid bounty" rather than a promise we cannot keep consistently.

The scope section is written for this repo, not copied. That was the point of doing three separate files: a disclosure policy whose scope describes someone else's software tells a researcher nothing about what to look at here.

This repo had no SECURITY.md, so a researcher who found something had no
documented way to report it privately and no idea what response to expect. For a
security product that is a real gap, not a paperwork one.

Mirrors the process already published in routeplane-ce (72-hour acknowledgement,
7-day assessment, 90-day coordinated disclosure, no paid bounty and we say so),
with the scope written for what THIS repo actually ships rather than copied.
@routeplane-ops
routeplane-ops merged commit c061462 into main Aug 6, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant