Skip to content

docs: clarify security report closure policy#1049

Merged
mldangelo-oai merged 2 commits intomainfrom
mdangelo/codex/security-report-resolution-policy
Apr 17, 2026
Merged

docs: clarify security report closure policy#1049
mldangelo-oai merged 2 commits intomainfrom
mdangelo/codex/security-report-resolution-policy

Conversation

@mldangelo-oai
Copy link
Copy Markdown
Contributor

Summary

  • Clarify that low-impact scanner coverage gaps can be closed without publishing a GHSA/CVE while still crediting reporters.
  • Add public credit for @mosebit's private TensorRT native-code detection-gap report.
  • Align the maintainer CVE process with the non-advisory closure path.

Validation

  • npx prettier --check CHANGELOG.md SECURITY.md docs/maintainers/cve-process.md
  • uv run ruff format modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/
  • uv run ruff check --fix modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/
  • uv run mypy modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest -n auto -m "not slow and not integration" --maxfail=1

@mldangelo-oai mldangelo-oai merged commit d53e445 into main Apr 17, 2026
5 checks passed
@mldangelo-oai mldangelo-oai deleted the mdangelo/codex/security-report-resolution-policy branch April 17, 2026 15:30
@github-actions github-actions bot mentioned this pull request Apr 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant