Skip to content

Add SECURITY.md with a vulnerability disclosure policy - #121

Open
34zY wants to merge 1 commit into
humanmade:masterfrom
34zY:patch-1
Open

Add SECURITY.md with a vulnerability disclosure policy#121
34zY wants to merge 1 commit into
humanmade:masterfrom
34zY:patch-1

Conversation

@34zY

@34zY 34zY commented Aug 29, 2026

Copy link
Copy Markdown

Add SECURITY.md — vulnerability disclosure policy

What

Adds a SECURITY.md that documents a private process for reporting security
vulnerabilities in this plugin.

Why

WP Simple SAML handles authentication (SAML SSO), so a clear, private channel
for security reports is valuable for both maintainers and users. This repo
currently has no SECURITY.md. Beyond documentation, this also affects
GitHub's "Report a vulnerability" button: it appears reliably on the
Security tab once a security policy is present, so adding this file makes
private reporting easier to discover.

Notes for maintainers

  • To fully enable the private report button, please also turn on
    Settings → Code security and analysis → Private vulnerability reporting.
  • The contact addresses (hello@humanmade.com, shady@humanmade.com) are
    taken from composer.json / README - please adjust to your preferred
    security contact.
  • The "Supported Versions" table currently lists latest (master), since I
    didn't see tagged releases. Please edit it to match y

Placement

Placed at the repository root; GitHub also recognizes `
you prefer to keep it there.

Expanded the security policy to include detailed reporting procedures, response processes, and coordinated disclosure guidelines.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant