Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add project-level security policy #2466

Open
lepras opened this issue May 2, 2024 · 2 comments
Open

Add project-level security policy #2466

lepras opened this issue May 2, 2024 · 2 comments
Labels
area: meta Repo management related stuff proposal A proposal for a new feature or an enhancement proposal-accepted An accepted proposal for a new feature or an enhancement

Comments

@lepras
Copy link

lepras commented May 2, 2024

Feature idea

I think you are the only guys who are maintaining an android Keyboard regularly. (Maybe Graphene OS but that's just bare bones AOSP)

As keyboard is atleast a ring 1 app you should have a github and project level security and/or privacy policy.

https://wiki.yoctoproject.org/wiki/SECURITY_file

https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository

Examples:

https://github.com/M66B/FairEmail/blob/master/PRIVACY.md

https://github.com/M66B/FairEmail/blob/master/SECURITY.md

I think you should pin this issue, but ofcourse yk better.

@lepras lepras added the proposal A proposal for a new feature or an enhancement label May 2, 2024
@patrickgold
Copy link
Member

Thanks for your proposal!

There's already a privacy policy on the official project website, see here: https://florisboard.org/legal/privacy/

As for the SECURITY.md, we could consider better defining how to report security vulnerabilities, will rename your issue accordingly.

@patrickgold patrickgold changed the title Security and/or Privacy Policy??? Add project-level security policy May 2, 2024
@patrickgold patrickgold added proposal-accepted An accepted proposal for a new feature or an enhancement area: meta Repo management related stuff labels May 2, 2024
@lepras
Copy link
Author

lepras commented May 2, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area: meta Repo management related stuff proposal A proposal for a new feature or an enhancement proposal-accepted An accepted proposal for a new feature or an enhancement
Projects
None yet
Development

No branches or pull requests

2 participants