Skip to content

Conversation

OrangeJerry
Copy link
Contributor

This PR adds a SECURITY.md file to document the project's security policies, including:

How to report vulnerabilities (e.g., via email/private issue)

Expected response time and disclosure process

Any security-related expectations for contributors

This file follows best practices for open-source projects (e.g., GitHub’s guidelines) to ensure transparent handling of security issues.

@CLAassistant
Copy link

CLAassistant commented May 27, 2025

CLA assistant check
All committers have signed the CLA.

Copy link
Member

@FateScript FateScript left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The "Dependency risks" section to avoid hardcoding requirements.txt.

The "Secure Development Practices" section to generalize the hash verification instructions.
Copy link
Member

@FateScript FateScript left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@FateScript FateScript merged commit 81f7dc3 into Megvii-BaseDetection:main Jun 8, 2025
1 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants