Skip to content

[codex] make security triage visible#747

Draft
h4x3rotab wants to merge 2 commits into
masterfrom
codex/security-docs-visible-triage
Draft

[codex] make security triage visible#747
h4x3rotab wants to merge 2 commits into
masterfrom
codex/security-docs-visible-triage

Conversation

@h4x3rotab

@h4x3rotab h4x3rotab commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add root SECURITY.md, README security entry points, and a security triage page for answered, accepted, hardening, and roadmap findings.
  • Route exploitable vulnerabilities to GitHub private security reporting or the listed security contact instead of public GitHub issues.
  • Clarify production security boundaries for dev KMS settings, KMS mTLS route enforcement, key derivation behavior, and timestamped KMS env-encryption key verification.
  • Align the security model with the README by documenting AMD SEV-SNP as new and experimental while keeping Intel TDX as the production path.

Why

Open public security issues made the repo look riskier than the maintainer position. The PR makes the security posture visible from the README, root security policy, docs index, tutorials, and SDK references without creating a public vulnerability-reporting issue template.

Validation

  • git diff --check
  • prek run --files README.md SECURITY.md docs/security/README.md sdk/go/README.md
  • Searched for stale responsible-disclosure wording, public-vulnerability-reporting wording, and unsafe fallback wording

Follow-up

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant