Handle vulnerabilities

Publish a vulnerability policy

Give researchers a safe reporting channel, scope, response expectations, and coordinated disclosure process.

8 minute lesson

~~~

Someone who finds a weakness should not have to guess how to reach you. Publish a clear security contact.

Use SECURITY.md and a monitored address or platform. State supported versions, safe-harbor expectations, prohibited testing, and what information helps reproduce the issue. Acknowledge reports, protect reporter data, and coordinate fixes and disclosure.

A researcher finds an authorization flaw and reports it in a public issue because the project has no security contact. The report exposes users before maintainers can investigate.

A policy must also protect the project from destructive testing. Clear scope and safe-harbor language help good-faith research without granting permission to access other users’ data.

Draft SECURITY.md with supported versions, a monitored private contact, useful report details, response expectations, and testing boundaries. Send a harmless test report and save proof that the responsible person receives and acknowledges it. Then test the public issue path and confirm it directs reporters to the private channel without exposing report contents.

Lesson completed

Take this course offline

Get every free book and course as PDF and EPUB files.

Get the download library →