Skip to content

docs: add org-wide security policy#21

Closed
spydon wants to merge 1 commit into
mainfrom
add-org-security-policy
Closed

docs: add org-wide security policy#21
spydon wants to merge 1 commit into
mainfrom
add-org-security-policy

Conversation

@spydon

@spydon spydon commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

What

Adds a SECURITY.md to supabase/.github so it becomes the default Security policy for every repository in the supabase org that doesn't define its own.

This sits alongside the org-wide defaults already hosted here (CODE_OF_CONDUCT.md, CONTRIBUTING.md, FUNDING.yml, PULL_REQUEST_TEMPLATE.md).

The content is the generic Supabase vulnerability disclosure policy already duplicated across individual repos (HackerOne VDP, scope, testing/reporting/disclosure guidelines).

Why

So we maintain the security policy in one place instead of copying SECURITY.md into every repository.

Follow-up

GitHub only shows this org default for repos that don't have their own SECURITY.md. Once this lands, the per-repo SECURITY.md files can be removed so the centralized one takes effect.

@spydon

spydon commented Jun 29, 2026

Copy link
Copy Markdown
Contributor Author

Closed in favor of #20

@spydon spydon closed this Jun 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant