Skip to content

Add SECURITY.md vulnerability disclosure policy - #11

Closed
AndrewAPico wants to merge 1 commit into
masterfrom
add-security-policy
Closed

AndrewAPico wants to merge 1 commit into
masterfrom
add-security-policy

Conversation

@AndrewAPico

Copy link
Copy Markdown
Contributor

Adds SECURITY.md to the root of this repository.

The policy covers private vulnerability reporting, response targets, supported versions, the CRA Article 13 security support period, scope, and third-party components. It is aligned with the EU Cyber Resilience Act (Regulation (EU) 2024/2847) and coordinated disclosure practice in ISO/IEC 29147 and ISO/IEC 30111.

Merging this enables the Security tab and the Report a vulnerability button on this repository.

The canonical copy lives in picotech/picosdk-repo-standards (PR #1). This file is a byte-identical copy; future changes should be made there first and redistributed.

Notes for review

  • This repository has an sbom/ folder, so the SBOM links in the policy resolve correctly.
  • The policy names the master branch under Supported versions and Support period. That is correct for this repository, but 6 of the organization's repositories default to main — wording such as "the repository's default branch" would travel better.
  • The support period is stated as "the supported lifetime of the associated PicoSDK release" and notes that it "must be confirmed and published by Pico's compliance function". That confirmation is still outstanding.

@MJBlackwell

Copy link
Copy Markdown
Contributor

Accepted

@MJBlackwell MJBlackwell closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants