Skip to content

docs: expand SECURITY.md with reporting channel, scope, and supported…#1277

Merged
mathuo merged 1 commit into
masterfrom
docs/security-md-update
May 13, 2026
Merged

docs: expand SECURITY.md with reporting channel, scope, and supported…#1277
mathuo merged 1 commit into
masterfrom
docs/security-md-update

Conversation

@mathuo
Copy link
Copy Markdown
Owner

@mathuo mathuo commented May 13, 2026

… versions

Add private vulnerability reporting via GitHub Security Advisories, publish a soft response SLA, define in/out-of-scope reports, and link the runtime security guide. Also fix SonarCube -> SonarCloud and add CodeQL alongside the existing static-analysis reference.

Description

Type of change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation
  • Refactor / cleanup
  • Build / CI / tooling

Affected packages

  • dockview-core
  • dockview (vanilla JS)
  • dockview-react
  • dockview-vue
  • dockview-angular
  • docs

How to test

Checklist

  • yarn lint:fix passes
  • yarn format passes
  • npm run gen has been run and generated files are up to date
  • yarn test passes
  • I have added or updated tests where applicable
  • Breaking changes are documented

… versions

Add private vulnerability reporting via GitHub Security Advisories,
publish a soft response SLA, define in/out-of-scope reports, and link
the runtime security guide. Also fix SonarCube -> SonarCloud and add
CodeQL alongside the existing static-analysis reference.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@mathuo mathuo merged commit cc92cc2 into master May 13, 2026
4 checks passed
@sonarqubecloud
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant