Skip to content

Add a security contact - #576

Closed
dasanchez wants to merge 1 commit into
masterfrom
add-security-contact
Closed

dasanchez wants to merge 1 commit into
masterfrom
add-security-contact

Conversation

@dasanchez

@dasanchez dasanchez commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Adds a way for people to report security vulnerabilities affecting hypha.coop or our work, via security@hypha.coop.

Changes

  • security.html
    • New /security/ page: what to report, what to include, what to expect, and a note to use the same address for vulnerabilities in our open-source repos instead of a public issue.
    • Not added to the main nav (no menu_title), so it stays a low-traffic utility page reached via the footer link, security.txt, or a direct link.
  • _includes/sections/footer.html
    • One line in the policies region, on every page: "Found a security issue? Please report it to security@hypha.coop."
  • .well-known/security.txt
    • RFC 9116 file with Contact, Policy (linking to /security/), Preferred-Languages, and Canonical. Expires is set to 2027-09-01 and needs renewing at least yearly.
  • .github/SECURITY.md
    • Short policy so GitHub surfaces a "Report a vulnerability" link on the repo's Security tab. Lives under .github/, so Jekyll doesn't publish it.
  • _config.yml
    • Adds security_email / security_email-hidden, following the existing email / email-hidden pattern used for hello@hypha.coop.
  • README.md
    • Short Security section pointing to the new page/file and flagging the security.txt renewal.

@dasanchez
dasanchez marked this pull request as ready for review September 22, 2026 17:53
@dasanchez
dasanchez marked this pull request as draft September 22, 2026 17:55
@dasanchez dasanchez closed this Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant