Update security section of README #1095
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Marked version: 0.3.17
Description
Recommendation from @davisjam via comment on #1083 seemed like a good one to me and more in keeping with standard operating procedures within the broader open source community regarding reporting and resolution of security issues (thanks for the education). Modified language to use "committers" and explicitly call out NPM owners.
Right now @chjj and I get all the security-related emails because we are the listed owners of the package in NPM. Having said that, I'm not sure there's much he and I are able to actually do to resolve them (for various reasons).
Might be nice to add emails (or something) for the committers on the AUTHORS page (see Django, for example)...?? I'm all about consent checks, especially with someone's contact information.
Collaborating with someone like @davisjam becomes difficult to accomplish via the internal discussion board (unless I'm showing my ignorance again) because he is not part of the "team" according to GitHub; so, email might be an appropriate alternative.
Contributor
Committer
In most cases, this should be a different person than the contributor.