Skip to content

docs(security): add vulnerability reporting policy - #83

Open
Edd88-pixel wants to merge 1 commit into
paypal:mainfrom
Edd88-pixel:docs/security-policy
Open

docs(security): add vulnerability reporting policy#83
Edd88-pixel wants to merge 1 commit into
paypal:mainfrom
Edd88-pixel:docs/security-policy

Conversation

@Edd88-pixel

Copy link
Copy Markdown

Why

The repository does not currently provide a security policy, leaving researchers and users without repository-specific guidance for privately reporting vulnerabilities or understanding the toolkit's security boundaries.

Changes

  • document the supported-version policy for actively maintained packages
  • direct repository vulnerabilities to GitHub private vulnerability reporting and PayPal service issues to the PayPal HackerOne program
  • define in-scope and out-of-scope security scenarios for an agent toolkit that can perform payment-related actions
  • add safe research, report-quality, coordinated disclosure, and recognition guidance

Validation

  • git diff origin/main...HEAD --check — passed
  • verified the required Markdown sections and reporting links — passed
  • confirmed private vulnerability reporting is enabled for this repository — passed
  • confirmed no open pull request currently proposes a SECURITY.md or security policy — passed
  • build, lint, typecheck, and runtime tests were not run because this is a documentation-only change

@Edd88-pixel
Edd88-pixel marked this pull request as ready for review July 25, 2026 12:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant