Skip to content

docs: make default security policy repository-neutral - #1

Open
the-luap wants to merge 1 commit into
mainfrom
docs/repository-neutral-security-policy
Open

docs: make default security policy repository-neutral#1
the-luap wants to merge 1 commit into
mainfrom
docs/repository-neutral-security-policy

Conversation

@the-luap

@the-luap the-luap commented Sep 7, 2026

Copy link
Copy Markdown

The organization's default security policy copies PicPeak application's obsolete 2.x support table. Repositories such as picpeak-usage inherit that table despite having independent versioning.

This makes the default policy apply across repositories: project-specific policies define supported releases, projects without versioned releases use their current default branch, and the PicPeak application links to its own support policy. Reports go privately to the affected repository when available, with info@picpeak.app as the fallback.

The 48-hour acknowledgment becomes a response target, application-specific security guarantees are removed, and the contributor guide's public security-issue link is replaced with the private-reporting policy.

Validation: git diff --check passes; relative policy links resolve and the linked PicPeak policy is reachable. Documentation only.

@the-luap the-luap added the documentation Improvements or additions to documentation label Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant