Skip to content

docs: add security policy - #218

Merged
alukach merged 1 commit into
mainfrom
docs/security-policy
Oct 3, 2026
Merged

alukach merged 1 commit into
mainfrom
docs/security-policy

Conversation

@alukach

@alukach alukach commented Oct 1, 2026

Copy link
Copy Markdown
Member

Adds a SECURITY.md directing reporters to GitHub's private vulnerability reporting (now enabled) instead of public issues, and sets expectations for acknowledgement, advisories/CVEs, and supported versions.

GitHub surfaces this file on the repo's Security tab and on the new-issue page.

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Claude finished @alukach's task in 7s —— View job


✅ No blocking issues — safe to merge.

SECURITY.md is a docs-only change. The links point at the correct repo paths, and the guidance is sound: it directs reporters to private reporting, asks for responsible disclosure, and limits support to the latest release. I didn't check that private vulnerability reporting is enabled on the repo, though the PR description says it is.

Simplify (ponytail)

  • Nothing to cut. The file is short, has no code or dependencies, and each section is needed.

💰 Estimated review cost: $0.09 · 0m06s · 4 turns

@github-actions github-actions Bot added the docs label Oct 1, 2026
@codecov

codecov Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 89.76%. Comparing base (be008ba) to head (cc3e754).
⚠️ Report is 4 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #218   +/-   ##
=======================================
  Coverage   89.76%   89.76%           
=======================================
  Files          30       30           
  Lines        1348     1348           
  Branches      180      180           
=======================================
  Hits         1210     1210           
  Misses         97       97           
  Partials       41       41           
Flag Coverage Δ
unittests 89.76% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@alukach
alukach marked this pull request as ready for review October 3, 2026 03:35
@alukach
alukach merged commit ed3a6d7 into main Oct 3, 2026
13 checks passed
@alukach
alukach deleted the docs/security-policy branch October 3, 2026 03:35
alukach pushed a commit that referenced this pull request Oct 6, 2026
🤖 I have created a release *beep* *boop*
---


##
[1.3.0](v1.2.0...v1.3.0)
(2026-10-06)


### Features

* add HTTPException handling in CQL2BuildFilter middleware
([#202](#202))
([5aeee7c](5aeee7c))
* **helm:** add servicemonitor support.
([#209](#209))
([979ceda](979ceda))


### Bug Fixes

* allow queryables endpoints for collections
([#204](#204))
([8b3d3c9](8b3d3c9))
* allow text in json response for CQl2RewriteLinksFilterMiddleware
([#205](#205))
([e55d85f](e55d85f))
* fetch existing record in-process for transaction validation
([#214](#214))
([3ffdd1d](3ffdd1d))
* keep headers from HTTPException responses built by middleware
([#212](#212))
([bd13264](bd13264))
* key OPA filter cache on full request context, not just Authorization
(GHSA-rm58-963w-252r)
([2a1c989](2a1c989))
* normalize root_path_skip_prefixes in ProcessLinksMiddleware
([#199](#199))
([1193600](1193600))
* reject ambiguous request paths before path-based checks
(GHSA-c42p-7w4w-p877)
([2a1c989](2a1c989))
* update reverse_proxy.py to return correct status code for upstream
request timeout
([#210](#210))
([be008ba](be008ba))
* URL-encode query string values when injecting CQL2 filter
(GHSA-c2p2-r6vx-2qc8)
([2a1c989](2a1c989))


### Documentation

* add security policy
([#218](#218))
([ed3a6d7](ed3a6d7))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: ds-release-bot[bot] <116609932+ds-release-bot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant