Description
The repository currently does not include a SECURITY.md file that explains how users, contributors, and security researchers can responsibly report vulnerabilities.
Because AIBF is designed to audit ATS hiring decisions and evaluate potential bias in recruitment workflows, establishing a clear vulnerability disclosure process would strengthen the project's security posture and governance practices.
Proposed Solution
- Add a
SECURITY.md file to the repository.
- Provide instructions for privately reporting security vulnerabilities.
- Define expected response and remediation timelines.
- Specify supported versions for security updates if applicable.
Benefits
- Encourages responsible vulnerability disclosure.
- Improves transparency and trust within the community.
- Aligns the project with widely adopted open-source security practices.
- Helps maintainers manage security reports more effectively.
Description
The repository currently does not include a
SECURITY.mdfile that explains how users, contributors, and security researchers can responsibly report vulnerabilities.Because AIBF is designed to audit ATS hiring decisions and evaluate potential bias in recruitment workflows, establishing a clear vulnerability disclosure process would strengthen the project's security posture and governance practices.
Proposed Solution
SECURITY.mdfile to the repository.Benefits