docs(security): replace unactionable email fallback with maintainer contact - #394
Conversation
…ontact SECURITY.md directed reporters without GitHub private vulnerability reporting access to email the maintainer listed in MAINTAINERS.md, but that file lists no email address. Replace the dead fallback with an instruction to contact a maintainer via their GitHub profile, which is always actionable given the roster in MAINTAINERS.md. Fixes #307 Signed-off-by: copilot-swe-agent <223556219+Copilot@users.noreply.github.com>
castrojo
left a comment
There was a problem hiding this comment.
Reviewed: changes in SECURITY.md direct reporters without private reporting to maintainer GitHub profiles.
However, GitHub private vulnerability reporting is currently disabled on this repository (enabled:false), and individual GitHub profiles do not provide a guaranteed private disclosure channel. Under GOVERNANCE.md and AGENTS.md, security policy changes require human maintainer review, and an actionable disclosure route should align with CNCF security standards (e.g., projects@cncf.io or enabling repository private vulnerability reporting).
Awaiting maintainer security review and decision on preferred private disclosure route.
|
Updated: replaced unactionable GitHub profile fallback with authoritative CNCF security team contact ( Awaiting independent review before merge per security policy governance. |
…jects@cncf.io Signed-off-by: Jorge O. Castro <jorge@projectbluefin.io> Signed-off-by: Jorge Castro <jorge.castro@gmail.com>
d01ff5d to
d9587b8
Compare
Summary
Closes #307
SECURITY.md's fallback instruction told reporters without GitHub private vulnerability reporting access to email the maintainer listed in MAINTAINERS.md, but that file lists no email address (only a name and GitHub profile link). This left the fallback channel unactionable.
This replaces the dead email fallback with an instruction to contact a maintainer directly via their GitHub profile, which is always actionable given the roster in MAINTAINERS.md, without inventing or exposing a personal email address that isn't otherwise documented.
Verification
Checklist
git commit -s)— hive: backend=copilot model=claude-haiku-4.5
🐝 Hive Agent:
contributor| SHA:9d394c4