Skip to content

docs: add security policy#1593

Merged
WilliamBergamin merged 1 commit into
mainfrom
security-policy
May 29, 2026
Merged

docs: add security policy#1593
WilliamBergamin merged 1 commit into
mainfrom
security-policy

Conversation

@WilliamBergamin
Copy link
Copy Markdown
Contributor

  • Adds a SECURITY.md to .github/ with vulnerability reporting instructions, threat model, and disclosure policy
  • Directs reporters to the Slack HackerOne bug bounty program
  • Defines in-scope vulnerabilities (signature bypass, token leakage, DoS, auth bypass) and out-of-scope issues

Category (place an x in each of the [ ])

  • bolt (Bolt for Java)
  • bolt-{sub modules} (Bolt for Java - optional modules)
  • slack-api-client (Slack API Clients)
  • slack-api-model (Slack API Data Models)
  • slack-api-*-kotlin-extension (Kotlin Extensions for Slack API Clients)
  • slack-app-backend (The primitive layer of Bolt for Java)

Requirements

Please read the Contributing guidelines and Code of Conduct before creating this issue or pull request. By submitting, you agree to those rules.

@WilliamBergamin WilliamBergamin self-assigned this May 28, 2026
@WilliamBergamin WilliamBergamin requested a review from a team as a code owner May 28, 2026 18:33
@WilliamBergamin WilliamBergamin added the docs M-T: Documentation work only label May 28, 2026
@codecov
Copy link
Copy Markdown

codecov Bot commented May 28, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 73.28%. Comparing base (45a122e) to head (9e41238).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff            @@
##               main    #1593   +/-   ##
=========================================
  Coverage     73.28%   73.28%           
  Complexity     4519     4519           
=========================================
  Files           478      478           
  Lines         14300    14300           
  Branches       1490     1490           
=========================================
  Hits          10480    10480           
  Misses         2932     2932           
  Partials        888      888           
Flag Coverage Δ
jdk-14 73.28% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

Copy link
Copy Markdown
Member

@zimeg zimeg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@WilliamBergamin Believe it or not I drink a coffee as these writings are read ☕ 🔏

@WilliamBergamin WilliamBergamin merged commit 5803580 into main May 29, 2026
7 checks passed
@WilliamBergamin WilliamBergamin deleted the security-policy branch May 29, 2026 14:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs M-T: Documentation work only

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants