Skip to content

docs: add SECURITY.md - #4

Merged
dpage merged 2 commits into
mainfrom
docs/security-policy
Aug 24, 2026
Merged

docs: add SECURITY.md#4
dpage merged 2 commits into
mainfrom
docs/security-policy

Conversation

@AntTheLimey

Copy link
Copy Markdown
Member

Adds SECURITY.md to the repository root. It names security@pgedge.com as
the single reporting route and points at the pgEdge Vulnerability Disclosure
Statement for scope, safe harbour and CVE handling.

The file is identical in every pgEdge product repository — nothing in it is
repo-specific.

Why an in-repo copy when there is an org default

pgEdge/.github carries the same file as an organisation default, which covers
every repository that has none of its own. Defaults do not appear in a
repository's file tree, git history, clones or release archives — only in the
Security tab. A product a customer clones or vendors should carry its own
policy, and OpenSSF Scorecard's security-policy check only looks in the
repository itself.

Draft on purpose — merge order matters

The only link in this file is https://docs.pgedge.com/security, and that URL
returns 404 today. Merging before the statement is live publishes a
security policy whose one actionable link is dead.

Merge order:

  1. docs: add vulnerability disclosure statement pgedge-docs#138 — publishes docs.pgedge.com/security. Out of
    draft and awaiting review.
  2. docs: add org-wide SECURITY.md default .github#6 — the org-wide default.
  3. This PR, alongside the other product repositories.

No action needed from you until #138 merges. Reviews welcome now.

Points at security@pgedge.com as the single reporting route and at the
pgEdge Vulnerability Disclosure Statement for scope, safe harbour and CVE
handling. Identical across every pgEdge product repository.

Do not merge before pgEdge/pgedge-docs#138 publishes
docs.pgedge.com/security; until it does, the only link in this file 404s.
The statement URL and the reporting address were bare text. Dave asked
for the URL to be a real link on pgedge-safesession#73: GitHub
autolinks it, but nothing guarantees another viewer will, and the two
actionable things in a security policy should not depend on a
renderer. The published statement at docs.pgedge.com/security already
writes the address as an explicit mailto link, so this keeps the two
documents consistent.

Identical across every repo carrying this file.
@AntTheLimey
AntTheLimey marked this pull request as ready for review August 24, 2026 13:46
@AntTheLimey
AntTheLimey requested a review from dpage August 24, 2026 13:56
@dpage
dpage merged commit 6ea735a into main Aug 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants