Files
msd-core/SECURITY.md
Tom Boucher 418db1ef36 docs(118): org-level security baseline RFC (draft) (#137)
* docs(118): scaffold docs/security/baseline.md with section structure

Creates docs/security/ directory and baseline.md with the full nine-section
RFC skeleton for the open-gsd org-level security baseline.

Sections: Status & scope, Minimum security controls (2.1–2.6), Incident-audit
checklist (NIST SP 800-61 Rev. 2), Reporting format, Ownership model, Rollout
plan, KPIs, Follow-up tracking checklist, References.

Source: https://csrc.nist.gov/publications/detail/sp/800-218/final (SSDF v1.1)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* docs(118): link baseline from SECURITY.md

Adds pointer section "Org-level security baseline" to SECURITY.md pointing
to docs/security/baseline.md. Per D1: no content duplication — SECURITY.md
retains its vulnerability-reporting focus; the new section links out only.

Source: https://docs.github.com/en/code-security/security-advisories

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* docs(118): fill PR #136 reference for reproducible env bootstrap (#117)

PR #136 was opened for #117 after this RFC was drafted; updating the
cross-reference. Replaces two "TBD" / "PR for #117" placeholders at
§ 2.5 and § 7 rollout table, and marks the §8 tracking checkbox as done.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 00:48:32 -04:00

1.2 KiB

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them via email to: security@gsd.build (or DM @glittercowboy on Discord/Twitter if email bounces)

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Fix timeline: Depends on severity, but we aim for:
    • Critical: 24-48 hours
    • High: 1 week
    • Medium/Low: Next release

Scope

Security issues in the GSD codebase that could:

  • Execute arbitrary code on user machines
  • Expose sensitive data (API keys, credentials)
  • Compromise the integrity of generated plans/code

Recognition

We appreciate responsible disclosure and will credit reporters in release notes (unless you prefer to remain anonymous).

Org-level security baseline

This file covers how to report individual vulnerabilities. For the broader org-wide security posture — scanner controls, incident-audit checklists, ownership model, and rollout plan — see:

docs/security/baseline.md