Skip to content

docs: add a link for reporting vulnerabilities within the project security policy - #44

Merged
purpleclay merged 1 commit into
mainfrom
43-include-link-in-security-doc
Aug 20, 2026
Merged

docs: add a link for reporting vulnerabilities within the project security policy#44
purpleclay merged 1 commit into
mainfrom
43-include-link-in-security-doc

Conversation

@purpleclay

@purpleclay purpleclay commented Aug 20, 2026

Copy link
Copy Markdown
Owner

closes #43

Summary by CodeRabbit

  • Documentation
    • Updated vulnerability reporting guidance with a direct private security advisory link.
    • Clarified that vulnerabilities must not be reported through public issues or discussed in pull requests.

…urity policy

Closes #43

Signed-off-by: purpleclay <purpleclaygh@gmail.com>
@coderabbitai

coderabbitai Bot commented Aug 20, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: ce651a1b-c533-4c06-9484-186a595c7aa2

📥 Commits

Reviewing files that changed from the base of the PR and between bc8e09b and c5279e5.

📒 Files selected for processing (1)
  • SECURITY.md

Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

The security policy now links directly to the repository’s private vulnerability reporting page. It also prohibits public issues and pull requests for vulnerability discussions.

Changes

Security reporting policy

Layer / File(s) Summary
Private vulnerability reporting instructions
SECURITY.md
The reporting section adds the direct private advisory URL and retains the prohibition on public disclosure channels.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Merge Risk: ⚪ Minimal · up to c5279

This localized documentation change adds a vulnerability-reporting link and has no actionable merge-blocking risk remaining beyond normal checks and review.

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the documentation change and the vulnerability-reporting link.
Linked Issues check ✅ Passed The changes add the required private vulnerability-reporting URL to SECURITY.md and support the linked issue objectives [#43].
Out of Scope Changes check ✅ Passed The changes are limited to vulnerability-reporting guidance in SECURITY.md and are related to the linked issue objectives.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch 43-include-link-in-security-doc

Comment @coderabbitai help to get the list of available commands.

@purpleclay
purpleclay merged commit 6e299f1 into main Aug 20, 2026
4 checks passed
@purpleclay
purpleclay deleted the 43-include-link-in-security-doc branch August 20, 2026 12:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SECURITY.md is missing a linked contact, capping OSSF Scorecard's Security-Policy check at 4/10

1 participant