docs: add an org-wide security policy - #5
Conversation
The org .github repo had a code of conduct and contributing guide but no security policy, so no repo advertised how to report a vulnerability. Adds SECURITY.md directing reporters to GitHub private vulnerability reporting (supported on these repos) with a private maintainer fallback, and notes the alpha support window and the untrusted-code scope (playground sandbox, compiler/runtime memory safety, shipped deps). Claude-Session: https://claude.ai/code/session_01NN6tAVpzkn8ZwE7M3hfyQk
|
| Filename | Overview |
|---|---|
| SECURITY.md | New org-wide security policy covering reporting via GitHub private vulnerability reporting, alpha support window, 90-day disclosure commitment, and playground/compiler scope — well-structured and complete |
Reviews (2): Last reviewed commit: "docs: add a disclosure timeline and clar..." | Re-trigger Greptile
Address review: state a 90-day coordinated-disclosure target with a coordinate-before-public-disclosure request, and note that private vulnerability reporting reaches the whole maintainer team (the primary channel), so a report never depends on one person - the named maintainer is only the fallback. Claude-Session: https://claude.ai/code/session_01NN6tAVpzkn8ZwE7M3hfyQk
|



Why
The org
.githubrepo has a code of conduct and a contributing guide but no security policy, so no muxlang repo advertised how to report a vulnerability. As an org-wide community-health file it applies to every repo that lacks its own.What
Adds
SECURITY.mdthat:🤖 Generated with Claude Code
https://claude.ai/code/session_01NN6tAVpzkn8ZwE7M3hfyQk