Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
dd7f434
docs: add security guidelines and SECURITY.md template
morri-son Apr 7, 2026
d57efb1
docs: improve practicality of security docs — make guidelines livable
morri-son Apr 7, 2026
14f8e38
docs: relax supply chain resolution timelines to match project maturity
morri-son Apr 7, 2026
9319ade
docs: integrate PR feedback — add operational security controls, Open…
morri-son Apr 9, 2026
187b4b3
docs: make vulnerability reporting platform-agnostic
morri-son Apr 15, 2026
559970e
docs: add container image scanning and license compliance scanning se…
morri-son Apr 17, 2026
d7b21b0
docs: align security guidelines with OpenSSF Security Baseline
morri-son Apr 17, 2026
5b7ba8d
docs: trim implementation details, add SLA rationale and exemplary pr…
morri-son Apr 20, 2026
f22cb73
consolidate section 8, Revise introduction statement and point to Ope…
morri-son Apr 20, 2026
7c60a71
add link to openssf Vulnerability Disclosure Guide
morri-son Apr 20, 2026
16f80dd
soften SLAs
morri-son Apr 21, 2026
aa3ed56
docs: condense security guidelines from 513 to 300 lines
morri-son Apr 23, 2026
5df2757
address PR review feedback from Skarlso
morri-son May 5, 2026
1cc7269
make push protection a MUST
morri-son May 5, 2026
636d843
Update security-guidelines/security-guidelines.md
morri-son May 18, 2026
f1e2f80
docs: clarify security guidelines scope is dev/build/release lifecycle
morrison-sap May 18, 2026
abac64e
docs: spell out CVSS judgment criteria in §7
morrison-sap May 18, 2026
8869bf3
docs: tie SCA scan frequency and visibility to OpenSSF Baseline
morrison-sap May 18, 2026
1de3d17
docs: anchor license allowlist to TSC + foundation licensing policy
morrison-sap May 18, 2026
81af4ce
docs: scope 2FA and deploy-key controls to SCM/CI/registry plane
morrison-sap May 18, 2026
ce961e1
docs: note Dependabot/Renovate update SHA-pinned actions automatically
morrison-sap May 18, 2026
62a6e76
docs: anchor org owner count and clarify repo admin role in §9.5
morrison-sap May 18, 2026
d6e7d25
docs: restructure maintainer vetting criteria into numbered list
morrison-sap May 18, 2026
0b51164
docs: add threat-modelling references to §9.7
morrison-sap May 18, 2026
f898ff5
docs: clarify Resolution column reference date in §10
morrison-sap May 18, 2026
ff09c49
docs: clarify multi-repo SECURITY.md fall-through (GitHub vs GitLab)
morrison-sap May 18, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Loading