Context
SECURITY.md provides private reporting and response targets, but the OpenSSF Silver criteria also ask for a documented internal response process and an explicit policy for reporter credit.
Follow-up to #22.
Acceptance criteria
- Document triage, severity assessment, remediation ownership, coordinated disclosure, and release steps.
- State how reporters can request credit or anonymity.
- Define how duplicate, invalid, and embargoed reports are handled without exposing sensitive details.
- Add a lightweight exercise or checklist that can validate the process without creating a real incident.
- Update the corresponding OpenSSF Silver answers with public evidence links.
Context
SECURITY.mdprovides private reporting and response targets, but the OpenSSF Silver criteria also ask for a documented internal response process and an explicit policy for reporter credit.Follow-up to #22.
Acceptance criteria