Skip to content

Missing SECURITY.md file #5561

@schlessera

Description

@schlessera

The project should include a SECURITY.md file to point people towards the right place to submit potential security vulnerabilities responsibly.

This can be done at https://hackerone.com/wordpress?type=team, the HackerOne account for the entire WordPress project.

We already have a piece of documentation here: https://make.wordpress.org/cli/handbook/contributions/contributing/#reporting-security-issues

However, a separate SECURITY.md file would be much more visible and obvious.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions