Skip to content

docs: add SECURITY.md - #420

Open
AntTheLimey wants to merge 1 commit into
mainfrom
docs/security-policy
Open

docs: add SECURITY.md#420
AntTheLimey wants to merge 1 commit into
mainfrom
docs/security-policy

Conversation

@AntTheLimey

Copy link
Copy Markdown
Member

Adds SECURITY.md to the repository root. It names security@pgedge.com as
the single reporting route and points at the pgEdge Vulnerability Disclosure
Statement at https://docs.pgedge.com/security for scope, safe harbour and CVE
handling.

The file is identical in every pgEdge product repository — nothing in it is
repo-specific — and byte-identical to the organisation default already merged
on pgEdge/.github.

Why an in-repo copy when there is an org default

pgEdge/.github carries the same file as an organisation default, which covers
every repository that has none of its own. Defaults do not appear in a
repository's file tree, git history, clones or release archives — only in the
Security tab. A product a customer clones or vendors should carry its own
policy, and OpenSSF Scorecard's security-policy check only looks in the
repository itself.

Ready to merge

The statement this file links to is live, and the same file is already on
main in the other pgEdge product repositories. This repository is one of the
seven that could not take the PR until push access was granted.

Points at security@pgedge.com as the single reporting route and at the
pgEdge Vulnerability Disclosure Statement at docs.pgedge.com/security
for scope, safe harbour and CVE handling. Identical across every pgEdge
product repository, and byte-identical to the organisation default on
pgEdge/.github.
@AntTheLimey
AntTheLimey requested a review from dpage September 3, 2026 12:57
@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 55ba3cd9-abf8-479b-a3c3-4dee1e930380

📥 Commits

Reviewing files that changed from the base of the PR and between 6a1fbc1 and 8dfa5f6.

📒 Files selected for processing (1)
  • SECURITY.md

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request adds SECURITY.md. The policy defines vulnerability reporting, acknowledgement timing, supported versions, disclosure scope, safe harbour terms, and advisory publication.

Changes

Security Policy

Layer / File(s) Summary
Security policy documentation
SECURITY.md
Documents reporting through security@pgedge.com, a five-business-day acknowledgement target, supported-version coverage, disclosure terms, safe harbour terms, and advisory publication under the Security tab.

Poem

A rabbit reads each line,
The patch grows clear beneath the moon,
Small changes hop in place,
Tests guard the garden path,
Reviews bloom before the dawn.

Merge Risk: ⚪ Minimal · up to 8dfa5

This adds a visible security reporting policy and disclosure reference without changing product behavior or runtime operation. No merge-readiness risk remains.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: adding SECURITY.md documentation.
Description check ✅ Passed The description directly explains the new SECURITY.md policy, reporting address, linked disclosure statement, and repository purpose.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/security-policy

Comment @coderabbitai help to get the list of available commands.

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 1 minor

Results:
1 new issue

Category Results
Comprehensibility 1 minor

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant