Skip to content

docs: add SECURITY.md - #30

Open
AntTheLimey wants to merge 1 commit into
mainfrom
docs/security-policy
Open

docs: add SECURITY.md#30
AntTheLimey wants to merge 1 commit into
mainfrom
docs/security-policy

Conversation

@AntTheLimey

Copy link
Copy Markdown
Member

Adds SECURITY.md to the repository root. It names security@pgedge.com as
the single reporting route and points at the pgEdge Vulnerability Disclosure
Statement at https://docs.pgedge.com/security for scope, safe harbour and CVE
handling.

The file is identical in every pgEdge product repository — nothing in it is
repo-specific — and byte-identical to the organisation default already merged
on pgEdge/.github.

Why an in-repo copy when there is an org default

pgEdge/.github carries the same file as an organisation default, which covers
every repository that has none of its own. Defaults do not appear in a
repository's file tree, git history, clones or release archives — only in the
Security tab. A product a customer clones or vendors should carry its own
policy, and OpenSSF Scorecard's security-policy check only looks in the
repository itself.

Ready to merge

The statement this file links to is live, and the same file is already on
main in the other pgEdge product repositories. This repository is one of the
seven that could not take the PR until push access was granted.

Points at security@pgedge.com as the single reporting route and at the
pgEdge Vulnerability Disclosure Statement at docs.pgedge.com/security
for scope, safe harbour and CVE handling. Identical across every pgEdge
product repository, and byte-identical to the organisation default on
pgEdge/.github.
@AntTheLimey
AntTheLimey requested a review from dpage September 3, 2026 12:57
@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 118a061d-3fa7-478d-9ed1-5f5fabf7b17e

📥 Commits

Reviewing files that changed from the base of the PR and between 2a60eb0 and 555898e.

📒 Files selected for processing (1)
  • SECURITY.md

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request adds SECURITY.md. The policy describes vulnerability reporting, acknowledgment, disclosure, supported versions, scope, safe harbour terms, testing authorization, and advisory publication.

Changes

Security Policy

Layer / File(s) Summary
Security policy documentation
SECURITY.md
Adds the vulnerability reporting process, five-business-day acknowledgment, supported versions policy, scope and safe harbour terms, Cloud testing authorization requirement, and advisory publication location.

Poem

A rabbit reads the security guide
Private reports now safely hide
Five business days bring a reply
Advisories bloom beneath the sky
Safe paths help each whisker stride

Merge Risk: ⚪ Minimal · up to 55589

This adds a repository security-reporting policy without changing runtime behavior or product functionality. No current merge-readiness risk is identified.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the addition of SECURITY.md documentation.
Description check ✅ Passed The description directly explains the new security policy, reporting contact, linked disclosure statement, and reason for adding the file to the repository.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/security-policy

Comment @coderabbitai help to get the list of available commands.

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant