Skip to content

chore: inherit org security policy - #291

Open
aljo242 wants to merge 1 commit into
mainfrom
policy/security-inherit
Open

aljo242 wants to merge 1 commit into
mainfrom
policy/security-inherit

Conversation

@aljo242

@aljo242 aljo242 commented Sep 18, 2026

Copy link
Copy Markdown

Removes this repo's SECURITY.md so it inherits the org default from cosmos/.github, which points at cosmos/security.

  • Sends reporters to hackerone.com/cosmos. The live program is Immunefi.
  • References security@interchain.io.

One policy instead of a copy per repo, so it can't go stale again.

@aljo242
aljo242 requested a review from a team as a code owner September 18, 2026 17:11
@greptile-apps

greptile-apps Bot commented Sep 18, 2026

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

The change is non-blocking for runtime behavior, but it should not merge until equivalent security-reporting guidance is available through the repository's actual owning organization.

Summary

This PR removes the repository-local vulnerability disclosure policy so that reporting guidance can be managed centrally.

  • Deletes the existing HackerOne and email reporting instructions.
  • The named cosmos/.github fallback does not apply to a repository owned by cometbft.

Reviews (1) · Last reviewed commit: "chore: inherit org security policy"

@greptile-apps

greptile-apps Bot commented Sep 18, 2026

Copy link
Copy Markdown

Comments Outside Diff

These findings sit on lines the diff does not cover, so they could not be posted inline. Each one leaves this list once its file changes.

  • P2 Policy Is Not Inherited SECURITY.md:33

    GitHub applies default community health files only to repositories owned by the same account. This repository is owned by cometbft, so deleting this file does not inherit the policy from cosmos/.github. If no equivalent policy exists under cometbft/.github, reporters will be left without vulnerability-reporting instructions. Please make the policy available through the owning organization before removing the local file.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant