Skip to content

start a SECURITY.md - #5210

Draft
jcupitt wants to merge 11 commits into
masterfrom
add-security.md
Draft

start a SECURITY.md#5210
jcupitt wants to merge 11 commits into
masterfrom
add-security.md

Conversation

@jcupitt

@jcupitt jcupitt commented Sep 5, 2026

Copy link
Copy Markdown
Member

Draft for discussion.

@jcupitt
jcupitt marked this pull request as draft September 5, 2026 09:25
Comment thread SECURITY.md Outdated
Comment on lines +34 to +38
Instead, report a [*confidential* issue in the github issue
tracker](https://github.com/libvips/libvips/-/issues/new?issue[confidential]=1),
with the “This issue is confidential” box checked. Please include as many
details as possible, including a minimal reproducible example of the issue,
and an idea of how exploitable/severe you think it is.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

GitHub has a security advisory feature with private reporting and CVE issuance. Maybe that would be a better workflow? They would go to https://github.com/libvips/libvips/security/advisories/new to submit something (e.g. Immich has https://github.com/immich-app/immich/security/advisories/new).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The advisory workflow is only useful after human review of an initial report. Descriptions and attempts at CVSS scoring provided by vulnerability reporters are usually inappropriate/incorrect and in almost all recent cases would not meet the AI policy.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, I think triage is a good first step, we have had quite a few false alarms.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and in almost all recent cases would not meet the AI policy

Though that only covers contributions intended to be merged to the project, I think, so AI bug reports are fine. Perhaps that's what you mean!

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, I was primarily thinking about LLM-generated code fixes, although anything to help reduce those really boring LLM-generated descriptions would also be welcome.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, we do get a lot of false alarms. FWIW they go to a triage tab before anything actually happens, so you can close them without publishing if they're just LLM spam.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would discourage using LLMs for bug/security reports as well, since they are often incorrect or highly misleading (and can therefore waste maintainers time and energy). For a more detailed rationale, see e.g.:
https://book.servo.org/contributing/getting-started.html#ai-contributions
or:
https://openjdk.org/legal/ai

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md
@jcupitt

jcupitt commented Sep 6, 2026

Copy link
Copy Markdown
Member Author

Thanks for the review! I've tried to incorporate your comments.

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
jcupitt and others added 5 commits September 6, 2026 12:04
Co-authored-by: Kleis Auke Wolthuizen <github@kleisauke.nl>
Co-authored-by: Kleis Auke Wolthuizen <github@kleisauke.nl>
Co-authored-by: Kleis Auke Wolthuizen <github@kleisauke.nl>

@kleisauke kleisauke left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A few nitpicks.

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
jcupitt and others added 4 commits September 6, 2026 12:18
Co-authored-by: Kleis Auke Wolthuizen <github@kleisauke.nl>
Co-authored-by: Kleis Auke Wolthuizen <github@kleisauke.nl>
Co-authored-by: Kleis Auke Wolthuizen <github@kleisauke.nl>
Co-authored-by: Kleis Auke Wolthuizen <github@kleisauke.nl>

@kleisauke kleisauke left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, but I'll leave the final review to @lovell, as this is more his area of expertise.

Comment thread SECURITY.md
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants