Skip to content

chore: add a security policy and reporting - #1049

Merged
mbevc1 merged 2 commits into
mainfrom
mbevc1-patch-1
Jul 28, 2026
Merged

chore: add a security policy and reporting#1049
mbevc1 merged 2 commits into
mainfrom
mbevc1-patch-1

Conversation

@mbevc1

@mbevc1 mbevc1 commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Updated the security policy to reflect supported versions and reporting procedures.

Checklist

Updated the security policy to reflect supported versions and reporting procedures.
Comment thread SECURITY.md Outdated
Co-authored-by: Marko Bevc <marko.bevc@gmail.com>
@mbevc1
mbevc1 enabled auto-merge (squash) July 28, 2026 14:38
@claude

claude Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Claude finished @mbevc1's task in 40s —— View job


PR Review: chore: add a security policy and reporting

Thanks for adding a security policy, @mbevc1 — having a clear, discoverable disclosure path is a real improvement for the repo. This is a documentation-only change (one new SECURITY.md), so the Go static-analysis checks (go build / go vet / go mod tidy) don't apply here.

The content is clear, well-structured, and the requested wording from your own review comment is already reflected in the file. A few small, non-blocking suggestions:

Suggestions

  1. Consider GitHub's private vulnerability reporting (line 7–9). Email is a fine primary channel, but GitHub's built-in private vulnerability reporting is more discoverable — it surfaces a "Report a vulnerability" button directly on the repo's Security tab. If it's enabled for this repo, worth mentioning it alongside security@kosli.com so reporters have a clear in-platform option.

  2. Tone on line 5 (minor/optional). The exclamation mark reads a little informal for a policy doc:

    Only v2 of the Kosli CLI is currently supported! Please try and use the latest release before reporting an issue.

    A period instead of ! would keep it matching the measured tone of the rest of the document. Purely stylistic — take it or leave it.

  3. "Supported Versions" format (optional). GitHub's default SECURITY.md template uses a small table for supported versions. The prose here is perfectly clear, so this is only worth it if you expect to track multiple concurrently-supported majors later.

Nothing blocking

No security, correctness, or maintainability concerns — it's a Markdown policy file with no executable impact. The reporting instructions are specific and actionable (description, repro, impact, evidence), and the "Our Commitment" section sets good expectations for researchers. Nice work. 👍
· mbevc1-patch-1

@mbevc1
mbevc1 merged commit 2398bd8 into main Jul 28, 2026
16 checks passed
@mbevc1
mbevc1 deleted the mbevc1-patch-1 branch July 28, 2026 14:46
@mbevc1 mbevc1 added the documentation Improvements or additions to documentation label Jul 28, 2026
@claude claude Bot mentioned this pull request Jul 28, 2026
3 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants