Skip to content

Unifiy the security.md in a single org #55

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
UlisesGascon opened this issue Mar 3, 2025 · 4 comments
Open

Unifiy the security.md in a single org #55

UlisesGascon opened this issue Mar 3, 2025 · 4 comments
Assignees

Comments

@UlisesGascon
Copy link
Member

Currently we have identical information in the tree orgs:

Ideally we can have only one (https://github.com/expressjs/.github/blob/master/SECURITY.md) and overwrite the other policies to point to the policy in Express.

I will work on it

@bjohansebas
Copy link
Member

What if we create an automation to ensure that the .github repositories have the same files?

@UlisesGascon
Copy link
Member Author

What if we create an automation to ensure that the .github repositories have the same files?

I already created the PRs (pillarjs/.github#3 and jshttp/.github#4) but if we prefer the automation I can work on that (cc: @expressjs/security-wg)

@wesleytodd
Copy link
Member

There is automation around which does this kind of thing, like npm's template-oss, but honestly I am not sure this is worth spending time on. There are not that many files, and we may have good reasons to differentiate things in some of these files across the orgs. I think we should just copy them and see when the next time someone touches them all at once before we work on automation.

@UlisesGascon
Copy link
Member Author

I'll keep this open in case we need to take action based on this comment: expressjs/.github#15 (comment).

Otherwise, we can close this in two weeks to allow time for the score to update organically.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants