Skip to content

docs: consolidate security policy to canonical website URL#10558

Closed
MarkAtwood wants to merge 1 commit into
wolfSSL:masterfrom
MarkAtwood:security-policy-canonical-pointer
Closed

docs: consolidate security policy to canonical website URL#10558
MarkAtwood wants to merge 1 commit into
wolfSSL:masterfrom
MarkAtwood:security-policy-canonical-pointer

Conversation

@MarkAtwood
Copy link
Copy Markdown
Contributor

Summary

  • Replace the inline security policy with a thin pointer to the canonical
    coordinated vulnerability disclosure policy at
    https://www.wolfssl.com/.well-known/vulnerability-disclosure-policy.txt
  • Keep PGP key fingerprint, contact info, and report template reference
    in .github/SECURITY.md (what GitHub shows on the Security tab)
  • Delete SECURITY-POLICY.md (now redundant — canonical policy lives on
    the website)
  • Update contact email from support@wolfssl.com to security@wolfssl.com
    to match the canonical policy

The website policy is the single source of truth, maintained for CRA
compliance. The report template (SECURITY-REPORT-TEMPLATE.md) is
unchanged.

Replace inline SECURITY-POLICY.md with a thin pointer in
.github/SECURITY.md to the canonical policy at
wolfssl.com/.well-known/vulnerability-disclosure-policy.txt.

Keeps PGP key, contact info, and report template reference.
Removes SECURITY-POLICY.md (now redundant).
Copilot AI review requested due to automatic review settings May 29, 2026 17:41
@MarkAtwood
Copy link
Copy Markdown
Contributor Author

Withdrawing — will consolidate approach.

@MarkAtwood MarkAtwood closed this May 29, 2026
@MarkAtwood MarkAtwood deleted the security-policy-canonical-pointer branch May 29, 2026 17:41
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@github-actions
Copy link
Copy Markdown

MemBrowse Memory Report

No memory changes detected for:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants