Efcore: Update to security template

Created on 26 Feb 2020  路  9Comments  路  Source: dotnet/efcore

So behind the scene something added a new commit https://github.com/dotnet/efcore/commit/659ecfd2842cb6710d40ecf39f671c28b437fc4f

(tell me more about automation taking over the world!)

Anyway, looking at aspnetcore repo the details have changed a little https://github.com/dotnet/aspnetcore/pull/19236
Our repo does not have security.MD in repo root, rather it is inside .github folder.

  • Which one do we keep?
  • Make sure the one we keep is up-to-date.
area-docs closed-fixed type-cleanup

Most helpful comment

Its your choice really, as long as all the info is there, including the bug bounty link then I'm good.

All 9 comments

@Pilchie We would like to understand:

  • What happened here that resulted in a bot adding a file to the repo without any PR or sign-off
  • What the guidance is for security.md especially given that we now have two files in two locations with conflicting information.

I'm not sure what this is. @mmitche do you know?

@terrajobst did this as a project for Barry

@terrajobst Ping.

@terrajobst Ping.

  • What happened here that resulted in a bot adding a file to the repo without any PR or sign-off

I've sent you an email with the details

  • What the guidance is for security.md especially given that we now have two files in two locations with conflicting information.

That I don't know. @blowdart needs to answer how he sees SECURTY.md vs. docs/security.md.

Its your choice really, as long as all the info is there, including the bug bounty link then I'm good.

@smitpatel Do you want to clean this up?

Yes, I do.

Was this page helpful?
0 / 5 - 0 ratings