Skip to content

Conversation

@stoyanovaantoaneta76-hash
Copy link

@stoyanovaantoaneta76-hash stoyanovaantoaneta76-hash commented Jan 24, 2026

Added a security policy document outlining supported versions and vulnerability reporting.

PR checklist

  • Read the contribution guidelines.
  • Pull Request title clearly describes the work in the pull request and Pull Request description provides details about how to validate the work. Missing information here may result in delayed response from the community.
  • Run the following to build the project and update samples:
    ./mvnw clean package || exit
    ./bin/generate-samples.sh ./bin/configs/*.yaml || exit
    ./bin/utils/export_docs_generators.sh || exit
    
    (For Windows users, please run the script in WSL)
    Commit all changed files.
    This is important, as CI jobs will verify all generator outputs of your HEAD commit as it would merge with master.
    These must match the expectations made by your contribution.
    You may regenerate an individual generator by passing the relevant config(s) as an argument to the script, for example ./bin/generate-samples.sh bin/configs/java*.
    IMPORTANT: Do NOT purge/delete any folders/files (e.g. tests) when regenerating the samples as manually written tests may be removed.
  • File the PR against the correct branch: master (upcoming 7.x.0 minor release - breaking changes with fallbacks), 8.0.x (breaking changes without fallbacks)
  • If your PR solves a reported issue, reference it using GitHub's linking syntax (e.g., having "fixes #123" present in the PR description)
  • If your PR is targeting a particular programming language, @mention the technical committee members, so they are more likely to review the pull request.

Summary by cubic

Add SECURITY.md with a supported versions table and a section for reporting vulnerabilities. Supports 5.1.x and 4.0.x; 5.0.x and <4.0 are not supported.

Written for commit df3e1fb. Summary will update on new commits.

Added a security policy document outlining supported versions and vulnerability reporting.
Copy link

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 issues found across 1 file

Prompt for AI agents (all issues)

Check if these issues are valid — if so, understand the root cause of each and fix them.


<file name="SECURITY.md">

<violation number="1" location="SECURITY.md:10">
P2: SECURITY.md still contains a template Supported Versions table (5.1.x/5.0.x/4.0.x) that conflicts with the project’s documented 7.x/6.x releases, so the security policy does not reflect actual supported versions.</violation>

<violation number="2" location="SECURITY.md:17">
P2: Reporting instructions are still placeholder template text, so the security policy lacks any real vulnerability reporting process.</violation>
</file>

Since this is your first cubic review, here's how it works:

  • cubic automatically reviews your code and comments on bugs and improvements
  • Teach cubic by replying to its comments. cubic learns from your replies and gets better over time
  • Ask questions if you need clarification on any suggestion

Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.


## Reporting a Vulnerability

Use this section to tell people how to report a vulnerability.
Copy link

@cubic-dev-ai cubic-dev-ai bot Jan 24, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: Reporting instructions are still placeholder template text, so the security policy lacks any real vulnerability reporting process.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At SECURITY.md, line 17:

<comment>Reporting instructions are still placeholder template text, so the security policy lacks any real vulnerability reporting process.</comment>

<file context>
@@ -0,0 +1,21 @@
+
+## Reporting a Vulnerability
+
+Use this section to tell people how to report a vulnerability.
+
+Tell them where to go, how often they can expect to get an update on a
</file context>
Fix with Cubic


| Version | Supported |
| ------- | ------------------ |
| 5.1.x | :white_check_mark: |
Copy link

@cubic-dev-ai cubic-dev-ai bot Jan 24, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: SECURITY.md still contains a template Supported Versions table (5.1.x/5.0.x/4.0.x) that conflicts with the project’s documented 7.x/6.x releases, so the security policy does not reflect actual supported versions.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At SECURITY.md, line 10:

<comment>SECURITY.md still contains a template Supported Versions table (5.1.x/5.0.x/4.0.x) that conflicts with the project’s documented 7.x/6.x releases, so the security policy does not reflect actual supported versions.</comment>

<file context>
@@ -0,0 +1,21 @@
+
+| Version | Supported          |
+| ------- | ------------------ |
+| 5.1.x   | :white_check_mark: |
+| 5.0.x   | :x:                |
+| 4.0.x   | :white_check_mark: |
</file context>
Fix with Cubic

Copy link
Author

@stoyanovaantoaneta76-hash stoyanovaantoaneta76-hash left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant