Skip to content

docs: security company policy updates#6677

Merged
blackboxsw merged 3 commits intocanonical:mainfrom
blackboxsw:security-filing
Jan 31, 2026
Merged

docs: security company policy updates#6677
blackboxsw merged 3 commits intocanonical:mainfrom
blackboxsw:security-filing

Conversation

@blackboxsw
Copy link
Collaborator

Add company compliant security docs and reference given internal policies.

Redact unnecessary duplication of data

Proposed Commit Message

docs: security company policy updates

Additional Context

Test Steps

Merge type

  • Squash merge using "Proposed Commit Message"
  • Rebase and merge unique commits. Requires commit messages per-commit each referencing the pull request number (#<PR_NUM>)

@blackboxsw blackboxsw marked this pull request as draft January 20, 2026 16:43
@blackboxsw blackboxsw marked this pull request as ready for review January 20, 2026 16:43
Copy link
Member

@holmanb holmanb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See previous comments

@blackboxsw blackboxsw requested a review from holmanb January 30, 2026 01:00
Copy link
Member

@holmanb holmanb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the updates @blackboxsw.

SECURITY.md Outdated
includes disclosure of any details related to the vulnerability or the
presence of a vulnerability itself. Violation of this policy may result in
removal from the list for the company or individual involved.
To report a security issue, file a [Private Security Report](https://github.com/canonical/cloud-init/security/advisories/new) with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"To report a security issue" is redundant due to the section header

... and any known mitigations for the issue.

SECURITY.md Outdated
presence of a vulnerability itself. Violation of this policy may result in
removal from the list for the company or individual involved.
To report a security issue, file a [Private Security Report](https://github.com/canonical/cloud-init/security/advisories/new) with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue.
The [Ubuntu Security disclosure and embargo policy](https://ubuntu.com/security/disclosure-policy) contains more information about what you can expect when you contact us and what we expect from you.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is also quite verbose.

How about just:

See the disclosure policy for more information.

@blackboxsw blackboxsw requested a review from holmanb January 30, 2026 23:51
Copy link
Member

@holmanb holmanb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@blackboxsw blackboxsw merged commit 4020383 into canonical:main Jan 31, 2026
22 checks passed
drzee99 pushed a commit to drzee99/cloud-init that referenced this pull request Feb 2, 2026
holmanb pushed a commit that referenced this pull request Feb 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants