Bertrand Delacretaz created SLING-10676:
-------------------------------------------

             Summary: Add a SECURITY.MD file to all our Git repositories
                 Key: SLING-10676
                 URL: https://issues.apache.org/jira/browse/SLING-10676
             Project: Sling
          Issue Type: Improvement
          Components: Documentation
            Reporter: Bertrand Delacretaz
            Assignee: Bertrand Delacretaz


We should add [https://github.com/apache/.github/blob/main/.github/SECURITY.md] 
to all our repositories, as per 
[https://twitter.com/iamamoose/status/1417104695626240001:]

{quote}All Apache projects follow the default ASF security policy; but not all 
have a github SECURITY․md file, and they get penalised, i.e. with lower 
#openssf scorecard scores 
([http://metrics.openssf.org|http://metrics.openssf.org/]) 
{quote}

Tentatively assigning to myself but if someone beats me to it I'd be happy!





--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to