Summary
Confirm GitHub Private Vulnerability Reporting (PVR) is enabled for the repo, document the reporting flow in SECURITY.md, and ensure CODEOWNERS routes security advisories to a defined responder group.
Background
SECURITY.md exists but does not currently make the GHSA private-reporting flow explicit. Enabling and documenting PVR is a low-effort, high-signal step that the OpenSSF Scorecard Security-Policy check rewards and that materially shortens the time from external report to triage.
Acceptance Criteria
Related
Summary
Confirm GitHub Private Vulnerability Reporting (PVR) is enabled for the repo, document the reporting flow in SECURITY.md, and ensure CODEOWNERS routes security advisories to a defined responder group.
Background
SECURITY.md exists but does not currently make the GHSA private-reporting flow explicit. Enabling and documenting PVR is a low-effort, high-signal step that the OpenSSF Scorecard
Security-Policycheck rewards and that materially shortens the time from external report to triage.Acceptance Criteria
gh apievidence captured in the PR)Security-Policycheck at maximum scoreRelated