Community health files: templates, security policy, org profile - #1
Merged
Merged
Conversation
Placed here so every repository inherits them. The bug form asks for the component, the platform and the version, because those three decide almost every answer and are what a report usually lacks. The pull-request template states the DCO sign-off that CI enforces, and asks what was verified rather than offering a checkbox that can mean nothing. Blank issues stay enabled: a report that fits no template is still a report. Signed-off-by: Simon Walz <contact@simonwalz.de>
It pointed at an Impressum page rather than a channel, promised only to respond "as quickly as possible", and said nothing about which versions get fixes. Now: GitHub private vulnerability reporting as the route, with an email fallback; acknowledgement in 5 working days and an assessment in 10; and the honest position on versions - pre-1.0, no backports, fixes land in the current release. Scope is stated in both directions, so a report about an application container running on CuOS is not mistaken for a CuOS vulnerability. Private vulnerability reporting has to be enabled per repository before the primary route works. Signed-off-by: Simon Walz <contact@simonwalz.de>
It is where a reader starts - it builds the images - but the overview listed cuos-iac twice and left it out entirely. Added as its own layer, plus a "Start here" line above the table. Signed-off-by: Simon Walz <contact@simonwalz.de>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue and PR templates for the whole org, a real reporting channel in SECURITY.md, and cuos-release added to the profile overview.