You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Low - security.md may not be recognized as the GitHub security policy file security.md is added in lowercase, but GitHub’s convention for repository security policies is SECURITY.md. If GitHub does not detect this file, the policy may not appear in the repository’s Security tab/community health surfaces, which undermines the reporting instructions added by this PR. Rename it to SECURITY.md.
No code security, VM, Rust, crypto, or performance issues are introduced by this diff; it only adds documentation.
This is a documentation-only PR — no code changes, no security or correctness concerns.
One actionable issue: file name casing
GitHub specifically recognizes SECURITY.md (all caps) in the repo root or .github/ directory. With the current security.md (lowercase) name, GitHub will not auto-discover the file and won't surface it in the repository's Security tab or link it from the "Report a vulnerability" button — which is the primary purpose of the document.
Recommendation: Rename to SECURITY.md or place at .github/SECURITY.md.
The "Our Response Process" section has no time-bound SLA (e.g., "acknowledge within 48 hours"). Reporters won't know if their submission was received.
The reward section mentions recognition in "our changelog or release notes" — worth confirming that venue actually exists and is maintained.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.