From 30e6e877b6cca8f9f6d93146042ce4de997da1ae Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Sun, 26 Jul 2026 14:41:09 +0100
Subject: [PATCH 1/5] chore: estate-wide security compliance
---
.github/workflows/codeql.yml | 1 +
.github/workflows/container-build.yml | 1 +
.github/workflows/dependabot-automerge.yml | 1 +
.github/workflows/dogfood-gate.yml | 1 +
.github/workflows/e2e.yml | 1 +
.github/workflows/estate-rules.yml | 1 +
.github/workflows/governance.yml | 1 +
.github/workflows/guix-policy.yml | 1 +
.github/workflows/hypatia-scan.yml | 1 +
.github/workflows/instant-sync.yml | 1 +
.github/workflows/mirror.yml | 1 +
.github/workflows/npm-bun-blocker.yml | 1 +
.github/workflows/openssf-compliance.yml | 1 +
.github/workflows/pages.yml | 1 +
.github/workflows/push-email-notify.yml | 1 +
.github/workflows/quality.yml | 1 +
.github/workflows/release.yml | 1 +
.github/workflows/rhodibot.yml | 1 +
.github/workflows/rust-ci.yml | 1 +
.github/workflows/scorecard.yml | 1 +
.github/workflows/secret-scanner.yml | 1 +
.github/workflows/security-policy.yml | 1 +
.github/workflows/sonarqube.yml | 1 +
.github/workflows/static-analysis-gate.yml | 1 +
.github/workflows/ts-blocker.yml | 1 +
.github/workflows/wellknown-enforcement.yml | 1 +
.github/workflows/workflow-linter.yml | 1 +
CODE_OF_CONDUCT.md | 327 ++++++++++++++++
SECURITY.md | 406 ++++++++++++++++++++
29 files changed, 760 insertions(+)
create mode 100644 CODE_OF_CONDUCT.md
create mode 100644 SECURITY.md
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index 498193c..dc8cdbc 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -11,6 +11,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
analyze:
diff --git a/.github/workflows/container-build.yml b/.github/workflows/container-build.yml
index 344d94a..0ca7758 100644
--- a/.github/workflows/container-build.yml
+++ b/.github/workflows/container-build.yml
@@ -16,6 +16,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml
index b46d71c..652ace4 100644
--- a/.github/workflows/dependabot-automerge.yml
+++ b/.github/workflows/dependabot-automerge.yml
@@ -42,6 +42,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false
permissions:
+ actions: read
contents: write # needed to enable auto-merge
pull-requests: write # needed to approve
# NB: keep narrow — do NOT add secrets: read or id-token: write here.
diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml
index ac46b73..9e1d71d 100644
--- a/.github/workflows/dogfood-gate.yml
+++ b/.github/workflows/dogfood-gate.yml
@@ -16,6 +16,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml
index eaed7cc..d4f3b2b 100644
--- a/.github/workflows/e2e.yml
+++ b/.github/workflows/e2e.yml
@@ -29,6 +29,7 @@ on:
- 'tests/**'
workflow_dispatch:
permissions: read-all
+ actions: read
concurrency:
group: e2e-${{ github.ref }}
cancel-in-progress: true
diff --git a/.github/workflows/estate-rules.yml b/.github/workflows/estate-rules.yml
index d17c3e8..30d13dc 100644
--- a/.github/workflows/estate-rules.yml
+++ b/.github/workflows/estate-rules.yml
@@ -18,6 +18,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
estate-rules:
diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml
index 8ec785b..92d9d89 100644
--- a/.github/workflows/governance.yml
+++ b/.github/workflows/governance.yml
@@ -12,6 +12,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/guix-policy.yml b/.github/workflows/guix-policy.yml
index 5308c27..79774cb 100644
--- a/.github/workflows/guix-policy.yml
+++ b/.github/workflows/guix-policy.yml
@@ -12,6 +12,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
check:
diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml
index 147d1ad..7619372 100644
--- a/.github/workflows/hypatia-scan.yml
+++ b/.github/workflows/hypatia-scan.yml
@@ -20,6 +20,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
+ actions: read
contents: read
security-events: write
diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml
index 619dca0..3c67981 100644
--- a/.github/workflows/instant-sync.yml
+++ b/.github/workflows/instant-sync.yml
@@ -10,6 +10,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false
permissions:
+ actions: read
contents: read
jobs:
dispatch:
diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml
index 9d9034f..8ea6fcf 100644
--- a/.github/workflows/mirror.yml
+++ b/.github/workflows/mirror.yml
@@ -8,6 +8,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false
permissions:
+ actions: read
contents: read
jobs:
mirror:
diff --git a/.github/workflows/npm-bun-blocker.yml b/.github/workflows/npm-bun-blocker.yml
index f5c2047..a6d1de4 100644
--- a/.github/workflows/npm-bun-blocker.yml
+++ b/.github/workflows/npm-bun-blocker.yml
@@ -12,6 +12,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
check:
diff --git a/.github/workflows/openssf-compliance.yml b/.github/workflows/openssf-compliance.yml
index 55d22bf..ba82ad2 100644
--- a/.github/workflows/openssf-compliance.yml
+++ b/.github/workflows/openssf-compliance.yml
@@ -12,6 +12,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
openssf-compliance:
diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml
index 8596374..50092a4 100644
--- a/.github/workflows/pages.yml
+++ b/.github/workflows/pages.yml
@@ -5,6 +5,7 @@ on:
branches: [main, master]
workflow_dispatch:
permissions:
+ actions: read
contents: read
pages: write
id-token: write
diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml
index 0816771..ce036e2 100644
--- a/.github/workflows/push-email-notify.yml
+++ b/.github/workflows/push-email-notify.yml
@@ -7,6 +7,7 @@ name: Push email notification
on:
push: {}
permissions:
+ actions: read
contents: read
jobs:
notify:
diff --git a/.github/workflows/quality.yml b/.github/workflows/quality.yml
index c288b82..6f459cc 100644
--- a/.github/workflows/quality.yml
+++ b/.github/workflows/quality.yml
@@ -13,6 +13,7 @@ concurrency:
permissions:
+ actions: read
contents: read
jobs:
lint:
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index 0826bca..fa6c50e 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -13,6 +13,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false
permissions:
+ actions: read
contents: read
jobs:
build:
diff --git a/.github/workflows/rhodibot.yml b/.github/workflows/rhodibot.yml
index 412d819..3dd8c4b 100644
--- a/.github/workflows/rhodibot.yml
+++ b/.github/workflows/rhodibot.yml
@@ -26,6 +26,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
canary:
diff --git a/.github/workflows/rust-ci.yml b/.github/workflows/rust-ci.yml
index 89427cc..d3e7847 100644
--- a/.github/workflows/rust-ci.yml
+++ b/.github/workflows/rust-ci.yml
@@ -11,6 +11,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
rust-ci:
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index 6b5541b..d3679ff 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -12,6 +12,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml
index 4a9129b..bd736fb 100644
--- a/.github/workflows/secret-scanner.yml
+++ b/.github/workflows/secret-scanner.yml
@@ -12,6 +12,7 @@ concurrency:
# (callee ⊆ caller), so the caller grants the union or the run startup-fails
# at plan time with zero jobs.
permissions:
+ actions: read
contents: read
# Single secret scanner. The standards reusable runs gitleaks (+ a Rust-secrets
# check). An inline TruffleHog job previously lived here, but the reusable
diff --git a/.github/workflows/security-policy.yml b/.github/workflows/security-policy.yml
index 024fe70..81d9566 100644
--- a/.github/workflows/security-policy.yml
+++ b/.github/workflows/security-policy.yml
@@ -12,6 +12,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
check:
diff --git a/.github/workflows/sonarqube.yml b/.github/workflows/sonarqube.yml
index 05b071c..c7ab029 100644
--- a/.github/workflows/sonarqube.yml
+++ b/.github/workflows/sonarqube.yml
@@ -15,6 +15,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
sonarqube:
diff --git a/.github/workflows/static-analysis-gate.yml b/.github/workflows/static-analysis-gate.yml
index b1021b3..a387fc8 100644
--- a/.github/workflows/static-analysis-gate.yml
+++ b/.github/workflows/static-analysis-gate.yml
@@ -11,6 +11,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
# ---------------------------------------------------------------------------
diff --git a/.github/workflows/ts-blocker.yml b/.github/workflows/ts-blocker.yml
index e572188..26a9263 100644
--- a/.github/workflows/ts-blocker.yml
+++ b/.github/workflows/ts-blocker.yml
@@ -12,6 +12,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
check:
diff --git a/.github/workflows/wellknown-enforcement.yml b/.github/workflows/wellknown-enforcement.yml
index 332161d..eb5a670 100644
--- a/.github/workflows/wellknown-enforcement.yml
+++ b/.github/workflows/wellknown-enforcement.yml
@@ -17,6 +17,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
validate:
diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml
index 250498f..cace278 100644
--- a/.github/workflows/workflow-linter.yml
+++ b/.github/workflows/workflow-linter.yml
@@ -16,6 +16,7 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md
new file mode 100644
index 0000000..8267cd4
--- /dev/null
+++ b/CODE_OF_CONDUCT.md
@@ -0,0 +1,327 @@
+# Code of Conduct
+
+
+
+## Our Pledge
+
+We as members, contributors, and leaders pledge to make participation in Squisher Corpus a harassment-free experience for everyone, regardless of age, body size, visible or invisible disability, ethnicity, sex characteristics, gender identity and expression, level of experience, education, socio-economic status, nationality, personal appearance, race, caste, colour, religion, or sexual identity and orientation.
+
+We pledge to act and interact in ways that contribute to an open, welcoming, diverse, inclusive, and healthy community.
+
+We recognise that a thriving open source community requires **psychological safety** — an environment where people can contribute, ask questions, make mistakes, and learn without fear of ridicule or retaliation.
+
+---
+
+## Our Standards
+
+### Expected Behaviour
+
+The following behaviours contribute to a positive environment:
+
+**Communication**
+- Using welcoming and inclusive language
+- Being respectful of differing viewpoints and experiences
+- Giving and gracefully accepting constructive feedback
+- Assuming good intent while addressing impact
+- Communicating clearly and patiently, especially with newcomers
+
+**Collaboration**
+- Focusing on what is best for the community
+- Showing empathy and kindness toward other community members
+- Being collaborative rather than competitive
+- Mentoring and supporting less experienced contributors
+- Celebrating others' contributions and successes
+
+**Professionalism**
+- Accepting responsibility and apologising to those affected by our mistakes
+- Learning from the experience and avoiding repetition
+- Respecting others' time and attention
+- Staying on topic in project spaces
+- Following project guidelines and conventions
+
+**Accessibility**
+- Using plain language and avoiding unnecessary jargon
+- Providing alt text for images and transcripts for audio/video
+- Being patient with those using assistive technologies
+- Accommodating different communication styles and needs
+- Recognising that not everyone communicates the same way
+
+### Unacceptable Behaviour
+
+The following behaviours are considered harassment and are unacceptable:
+
+**Harassment**
+- The use of sexualised language or imagery, and sexual attention or advances of any kind
+- Trolling, insulting or derogatory comments, and personal or political attacks
+- Public or private harassment
+- Deliberate intimidation, stalking, or following (online or in-person)
+- Unwelcome physical contact or simulated physical contact (e.g., emoji)
+- Sustained disruption of talks, events, or online discussions
+
+**Discrimination**
+- Discriminatory jokes and language
+- Posting or threatening to post others' personally identifying information ("doxing")
+- Advocating for, or encouraging, any of the above behaviour
+- Microaggressions — subtle, often unintentional, discriminatory comments or actions
+
+**Professional Misconduct**
+- Publishing others' private information without explicit permission
+- Misrepresenting affiliation or contributions
+- Plagiarism or claiming credit for others' work
+- Retaliating against anyone who reports a Code of Conduct violation
+- Other conduct which could reasonably be considered inappropriate in a professional setting
+
+### Grey Areas
+
+Some situations require judgement. When uncertain:
+
+- **Intent vs Impact**: Good intentions do not excuse harmful impact. Focus on making things right.
+- **Power Dynamics**: Those with more power (maintainers, employers, experienced contributors) must be especially mindful of their impact.
+- **Cultural Differences**: What's acceptable varies by culture. When in doubt, err on the side of caution and ask.
+- **Humour**: Jokes at others' expense are rarely funny to everyone. Punch up, not down.
+
+---
+
+## Scope
+
+This Code of Conduct applies within all community spaces, including:
+
+**Online Spaces**
+- Repository discussions, issues, and pull/merge requests
+- Project chat channels (Matrix, Discord, Slack, IRC)
+- Mailing lists and forums
+- Social media when representing the project
+- Video calls and virtual meetings
+
+**In-Person Spaces**
+- Conferences, meetups, and events
+- Workshops and training sessions
+- Any gathering where you represent the project
+
+**Representation**
+This Code of Conduct also applies when an individual is officially representing the community in public spaces. Examples include:
+
+- Using an official project email address
+- Posting via an official social media account
+- Acting as an appointed representative at an event
+- Speaking on behalf of the project
+
+---
+
+## Enforcement
+
+### Reporting
+
+If you experience or witness unacceptable behaviour, or have any other concerns, please report it as soon as possible.
+
+**How to Report**
+
+| Method | Details | Best For |
+|--------|---------|----------|
+| **Email** | j.d.a.jewell@open.ac.uk | Detailed reports, sensitive matters |
+| **Private Message** | Contact any maintainer directly | Quick questions, minor issues |
+| **Anonymous Form** | [Link to form if available] | When you need anonymity |
+
+**What to Include**
+
+- Your contact information (unless anonymous)
+- Names/usernames of those involved
+- Description of what happened
+- When and where it occurred
+- Any witnesses
+- Any supporting evidence (screenshots, links)
+- How you would like us to respond (if you have a preference)
+
+**What Happens Next**
+
+1. You will receive acknowledgment within **48 hours**
+2. The maintainers will review the report
+3. We may ask for additional information
+4. We will determine appropriate action
+5. We will inform you of the outcome (respecting others' privacy)
+
+### Confidentiality
+
+All reports will be handled with discretion:
+
+- Reporter identity is protected by default
+- Details are shared only with those who need to know
+- We will ask before naming you in any communication
+- Anonymous reports are accepted and investigated
+
+### Conflicts of Interest
+
+If a maintainers member is involved in an incident:
+
+- They will recuse themselves from the process
+- Another maintainer or external party will handle the report
+- We will disclose any potential conflicts
+
+---
+
+## Enforcement Guidelines
+
+The maintainers will follow these guidelines in determining consequences:
+
+### 1. Correction
+
+**Community Impact**: Use of inappropriate language or other behaviour deemed unprofessional or unwelcome.
+
+**Consequence**: A private, written warning providing clarity around the nature of the violation and an explanation of why the behaviour was inappropriate. A public apology may be requested.
+
+**Duration**: Immediate
+
+### 2. Warning
+
+**Community Impact**: A violation through a single incident or series of actions.
+
+**Consequence**: A warning with consequences for continued behaviour. No interaction with the people involved, including unsolicited interaction with those enforcing the Code of Conduct, for a specified period. This includes avoiding interactions in community spaces as well as external channels like social media. Violating these terms may lead to a temporary or permanent ban.
+
+**Duration**: 1-4 weeks
+
+### 3. Temporary Ban
+
+**Community Impact**: A serious violation of community standards, including sustained inappropriate behaviour.
+
+**Consequence**: A temporary ban from any sort of interaction or public communication with the community for a specified period. No public or private interaction with the people involved, including unsolicited interaction with those enforcing the Code of Conduct, is allowed during this period. Violating these terms may lead to a permanent ban.
+
+**Duration**: 1-6 months
+
+### 4. Permanent Ban
+
+**Community Impact**: Demonstrating a pattern of violation of community standards, including sustained inappropriate behaviour, harassment of an individual, or aggression toward or disparagement of classes of individuals.
+
+**Consequence**: A permanent ban from any sort of public interaction within the community.
+
+**Duration**: Permanent (with appeal rights after 12 months)
+
+### Enforcement Across Perimeters
+
+For contributors with elevated access (Perimeter 2 or 1):
+
+| Level | Additional Consequence |
+|-------|----------------------|
+| Correction | Noted in contributor record |
+| Warning | Access privileges may be temporarily reduced |
+| Temporary Ban | Access reduced to Perimeter 3 for ban duration |
+| Permanent Ban | All access revoked |
+
+---
+
+## Appeals
+
+If you believe an enforcement decision was made in error:
+
+1. **Wait 7 days** after the decision (cooling-off period)
+2. **Email** j.d.a.jewell@open.ac.uk with subject line "Appeal: [Original Report ID]"
+3. **Explain** why you believe the decision should be reconsidered
+4. **Provide** any new information not previously available
+
+**Appeals Process**
+
+- Appeals are reviewed by a different maintainers member than the original
+- You will receive a response within 14 days
+- The appeals decision is final
+- You may only appeal once per incident
+
+**Grounds for Appeal**
+
+- Procedural errors in the original investigation
+- New evidence not previously available
+- Disproportionate response to the violation
+- Misunderstanding of facts
+
+---
+
+## Supporting Those Who Report
+
+We are committed to supporting those who report violations:
+
+**We Will**
+- Believe and take all reports seriously
+- Respect your privacy and confidentiality preferences
+- Keep you informed of progress (if you wish)
+- Take steps to protect you from retaliation
+- Provide resources if you need support
+
+**We Will Not**
+- Require you to confront the person directly
+- Dismiss reports without investigation
+- Reveal your identity without consent
+- Tolerate retaliation against reporters
+- Rush you to make decisions
+
+---
+
+## Prevention
+
+Beyond enforcement, we actively work to prevent issues:
+
+**Onboarding**
+- All contributors are expected to read this Code of Conduct
+- Perimeter 2 applicants must confirm they've read and understood it
+- Maintainers receive additional training on enforcement
+
+**Culture**
+- We model the behaviour we expect
+- We intervene early when we see potential issues
+- We thank people for positive contributions
+- We create opportunities for diverse voices
+
+**Review**
+- This Code of Conduct is reviewed annually
+- Community feedback is welcomed
+- Changes are communicated clearly
+
+---
+
+## Acknowledgments
+
+This Code of Conduct is adapted from:
+
+- [Contributor Covenant](https://www.contributor-covenant.org/), version 2.1
+- [Django Code of Conduct](https://www.djangoproject.com/conduct/)
+- [Rust Code of Conduct](https://www.rust-lang.org/policies/code-of-conduct)
+- [Python Community Code of Conduct](https://www.python.org/psf/conduct/)
+
+We thank these communities for their leadership in creating welcoming spaces.
+
+---
+
+## Questions?
+
+If you have questions about this Code of Conduct:
+
+- Open a [Discussion](https://github.com/hyperpolymath/squisher-corpus/discussions) (for general questions)
+- Email j.d.a.jewell@open.ac.uk (for private questions)
+- Contact any maintainer directly
+
+---
+
+## Summary
+
+**Be kind. Be respectful. Be collaborative.**
+
+We're all here because we care about this project. Let's make it a place where everyone can do their best work.
+
+---
+
+Last updated: 2026 · Based on Contributor Covenant 2.1
diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 0000000..1ed5203
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,406 @@
+# Security Policy
+
+
+
+We take security seriously. We appreciate your efforts to responsibly disclose vulnerabilities and will make every effort to acknowledge your contributions.
+
+## Table of Contents
+
+- [Reporting a Vulnerability](#reporting-a-vulnerability)
+- [What to Include](#what-to-include)
+- [Response Timeline](#response-timeline)
+- [Disclosure Policy](#disclosure-policy)
+- [Scope](#scope)
+- [Safe Harbour](#safe-harbour)
+- [Recognition](#recognition)
+- [Security Updates](#security-updates)
+- [Security Best Practices](#security-best-practices)
+
+---
+
+## Reporting a Vulnerability
+
+### Preferred Method: GitHub Security Advisories
+
+The preferred method for reporting security vulnerabilities is through GitHub's Security Advisory feature:
+
+1. Navigate to [Report a Vulnerability](https://github.com/hyperpolymath/squisher-corpus/security/advisories/new)
+2. Click **"Report a vulnerability"**
+3. Complete the form with as much detail as possible
+4. Submit — we'll receive a private notification
+
+This method ensures:
+
+- End-to-end encryption of your report
+- Private discussion space for collaboration
+- Coordinated disclosure tooling
+- Automatic credit when the advisory is published
+
+### Alternative: Encrypted Email
+
+If you cannot use GitHub Security Advisories, you may email us directly:
+
+| | |
+|---|---|
+| **Email** | j.d.a.jewell@open.ac.uk |
+| **PGP Key** | [Download Public Key](https://github.com/hyperpolymath.gpg) |
+| **Fingerprint** | `TBD` |
+
+```bash
+# Import our PGP key
+curl -sSL https://github.com/hyperpolymath.gpg | gpg --import
+
+# Verify fingerprint
+gpg --fingerprint j.d.a.jewell@open.ac.uk
+
+# Encrypt your report
+gpg --armor --encrypt --recipient j.d.a.jewell@open.ac.uk report.txt
+```
+
+> **⚠️ Important:** Do not report security vulnerabilities through public GitHub issues, pull requests, discussions, or social media.
+
+---
+
+## What to Include
+
+A good vulnerability report helps us understand and reproduce the issue quickly.
+
+### Required Information
+
+- **Description**: Clear explanation of the vulnerability
+- **Impact**: What an attacker could achieve (confidentiality, integrity, availability)
+- **Affected versions**: Which versions/commits are affected
+- **Reproduction steps**: Detailed steps to reproduce the issue
+
+### Helpful Additional Information
+
+- **Proof of concept**: Code, scripts, or screenshots demonstrating the vulnerability
+- **Attack scenario**: Realistic attack scenario showing exploitability
+- **CVSS score**: Your assessment of severity (use [CVSS 3.1 Calculator](https://www.first.org/cvss/calculator/3.1))
+- **CWE ID**: Common Weakness Enumeration identifier if known
+- **Suggested fix**: If you have ideas for remediation
+- **References**: Links to related vulnerabilities, research, or advisories
+
+### Example Report Structure
+
+```markdown
+## Summary
+[One-sentence description of the vulnerability]
+
+## Vulnerability Type
+[e.g., SQL Injection, XSS, SSRF, Path Traversal, etc.]
+
+## Affected Component
+[File path, function name, API endpoint, etc.]
+
+## Affected Versions
+[Version range or specific commits]
+
+## Severity Assessment
+- CVSS 3.1 Score: [X.X]
+- CVSS Vector: [CVSS:3.1/AV:X/AC:X/PR:X/UI:X/S:X/C:X/I:X/A:X]
+
+## Description
+[Detailed technical description]
+
+## Steps to Reproduce
+1. [First step]
+2. [Second step]
+3. [...]
+
+## Proof of Concept
+[Code, curl commands, screenshots, etc.]
+
+## Impact
+[What can an attacker achieve?]
+
+## Suggested Remediation
+[Optional: your ideas for fixing]
+
+## References
+[Links to related issues, CVEs, research]
+```
+
+---
+
+## Response Timeline
+
+We commit to the following response times:
+
+| Stage | Timeframe | Description |
+|-------|-----------|-------------|
+| **Initial Response** | 48 hours | We acknowledge receipt and confirm we're investigating |
+| **Triage** | 7 days | We assess severity, confirm the vulnerability, and estimate timeline |
+| **Status Update** | Every 7 days | Regular updates on remediation progress |
+| **Resolution** | 90 days | Target for fix development and release (complex issues may take longer) |
+| **Disclosure** | 90 days | Public disclosure after fix is available (coordinated with you) |
+
+> **Note:** These are targets, not guarantees. Complex vulnerabilities may require more time. We'll communicate openly about any delays.
+
+---
+
+## Disclosure Policy
+
+We follow **coordinated disclosure** (also known as responsible disclosure):
+
+1. **You report** the vulnerability privately
+2. **We acknowledge** and begin investigation
+3. **We develop** a fix and prepare a release
+4. **We coordinate** disclosure timing with you
+5. **We publish** security advisory and fix simultaneously
+6. **You may publish** your research after disclosure
+
+### Our Commitments
+
+- We will not take legal action against researchers who follow this policy
+- We will work with you to understand and resolve the issue
+- We will credit you in the security advisory (unless you prefer anonymity)
+- We will notify you before public disclosure
+- We will publish advisories with sufficient detail for users to assess risk
+
+### Your Commitments
+
+- Report vulnerabilities promptly after discovery
+- Give us reasonable time to address the issue before disclosure
+- Do not access, modify, or delete data beyond what's necessary to demonstrate the vulnerability
+- Do not degrade service availability (no DoS testing on production)
+- Do not share vulnerability details with others until coordinated disclosure
+
+### Disclosure Timeline
+
+```
+Day 0 You report vulnerability
+Day 1-2 We acknowledge receipt
+Day 7 We confirm vulnerability and share initial assessment
+Day 7-90 We develop and test fix
+Day 90 Coordinated public disclosure
+ (earlier if fix is ready; later by mutual agreement)
+```
+
+If we cannot reach agreement on disclosure timing, we default to 90 days from your initial report.
+
+---
+
+## Scope
+
+### In Scope ✅
+
+The following are within scope for security research:
+
+- This repository (`hyperpolymath/squisher-corpus`) and all its code
+- Official releases and packages published from this repository
+- Documentation that could lead to security issues
+- Build and deployment configurations in this repository
+- Dependencies (report here, we'll coordinate with upstream)
+
+### Out of Scope ❌
+
+The following are **not** in scope:
+
+- Third-party services we integrate with (report directly to them)
+- Social engineering attacks against maintainers
+- Physical security
+- Denial of service attacks against production infrastructure
+- Spam, phishing, or other non-technical attacks
+- Issues already reported or publicly known
+- Theoretical vulnerabilities without proof of concept
+
+### Qualifying Vulnerabilities
+
+We're particularly interested in:
+
+- Remote code execution
+- SQL injection, command injection, code injection
+- Authentication/authorisation bypass
+- Cross-site scripting (XSS) and cross-site request forgery (CSRF)
+- Server-side request forgery (SSRF)
+- Path traversal / local file inclusion
+- Information disclosure (credentials, PII, secrets)
+- Cryptographic weaknesses
+- Deserialisation vulnerabilities
+- Memory safety issues (buffer overflows, use-after-free, etc.)
+- Supply chain vulnerabilities (dependency confusion, etc.)
+- Significant logic flaws
+
+### Non-Qualifying Issues
+
+The following generally do not qualify as security vulnerabilities:
+
+- Missing security headers on non-sensitive pages
+- Clickjacking on pages without sensitive actions
+- Self-XSS (requires victim to paste code)
+- Missing rate limiting (unless it enables a specific attack)
+- Username/email enumeration (unless high-risk context)
+- Missing cookie flags on non-sensitive cookies
+- Software version disclosure
+- Verbose error messages (unless exposing secrets)
+- Best practice deviations without demonstrable impact
+
+---
+
+## Safe Harbour
+
+We support security research conducted in good faith.
+
+### Our Promise
+
+If you conduct security research in accordance with this policy:
+
+- ✅ We will not initiate legal action against you
+- ✅ We will not report your activity to law enforcement
+- ✅ We will work with you in good faith to resolve issues
+- ✅ We consider your research authorised under the Computer Fraud and Abuse Act (CFAA), UK Computer Misuse Act, and similar laws
+- ✅ We waive any potential claim against you for circumvention of security controls
+
+### Good Faith Requirements
+
+To qualify for safe harbour, you must:
+
+- Comply with this security policy
+- Report vulnerabilities promptly
+- Avoid privacy violations (do not access others' data)
+- Avoid service degradation (no destructive testing)
+- Not exploit vulnerabilities beyond proof-of-concept
+- Not use vulnerabilities for profit (beyond bug bounties where offered)
+
+> **⚠️ Important:** This safe harbour does not extend to third-party systems. Always check their policies before testing.
+
+---
+
+## Recognition
+
+We believe in recognising security researchers who help us improve.
+
+### Hall of Fame
+
+Researchers who report valid vulnerabilities will be acknowledged in our [Security Acknowledgments](SECURITY-ACKNOWLEDGMENTS.md) (unless they prefer anonymity).
+
+Recognition includes:
+
+- Your name (or chosen alias)
+- Link to your website/profile (optional)
+- Brief description of the vulnerability class
+- Date of report
+
+### What We Offer
+
+- ✅ Public credit in security advisories
+- ✅ Acknowledgment in release notes
+- ✅ Entry in our Hall of Fame
+- ✅ Reference/recommendation letter upon request (for significant findings)
+
+### What We Don't Currently Offer
+
+- ❌ Monetary bug bounties
+- ❌ Hardware or swag
+- ❌ Paid security research contracts
+
+> **Note:** We're a community project with limited resources. Your contributions help everyone who uses this software.
+
+---
+
+## Security Updates
+
+### Receiving Updates
+
+To stay informed about security updates:
+
+- **Watch this repository**: Click "Watch" → "Custom" → Select "Security alerts"
+- **GitHub Security Advisories**: Published at [Security Advisories](https://github.com/hyperpolymath/squisher-corpus/security/advisories)
+- **Release notes**: Security fixes noted in [CHANGELOG](CHANGELOG.md)
+
+### Update Policy
+
+| Severity | Response |
+|----------|----------|
+| **Critical/High** | Patch release as soon as fix is ready |
+| **Medium** | Included in next scheduled release (or earlier) |
+| **Low** | Included in next scheduled release |
+
+### Supported Versions
+
+
+
+| Version | Supported | Notes |
+|---------|-----------|-------|
+| `main` branch | ✅ Yes | Latest development |
+| Latest release | ✅ Yes | Current stable |
+| Previous minor release | ✅ Yes | Security fixes backported |
+| Older versions | ❌ No | Please upgrade |
+
+---
+
+## Security Best Practices
+
+When using Squisher Corpus, we recommend:
+
+### General
+
+- Keep dependencies up to date
+- Use the latest stable release
+- Subscribe to security notifications
+- Review configuration against security documentation
+- Follow principle of least privilege
+
+### For Contributors
+
+- Never commit secrets, credentials, or API keys
+- Use signed commits (`git config commit.gpgsign true`)
+- Review dependencies before adding them
+- Run security linters locally before pushing
+- Report any concerns about existing code
+
+---
+
+## Additional Resources
+
+- [Our PGP Public Key](https://github.com/hyperpolymath.gpg)
+- [Security Advisories](https://github.com/hyperpolymath/squisher-corpus/security/advisories)
+- [Changelog](CHANGELOG.md)
+- [Contributing Guidelines](CONTRIBUTING.md)
+- [CVE Database](https://cve.mitre.org/)
+- [CVSS Calculator](https://www.first.org/cvss/calculator/3.1)
+
+---
+
+## Contact
+
+| Purpose | Contact |
+|---------|---------|
+| **Security issues** | [Report via GitHub](https://github.com/hyperpolymath/squisher-corpus/security/advisories/new) or j.d.a.jewell@open.ac.uk |
+| **General questions** | [GitHub Discussions](https://github.com/hyperpolymath/squisher-corpus/discussions) |
+| **Other enquiries** | See [README](README.md) for contact information |
+
+---
+
+## Policy Changes
+
+This security policy may be updated from time to time. Significant changes will be:
+
+- Committed to this repository with a clear commit message
+- Noted in the changelog
+- Announced via GitHub Discussions (for major changes)
+
+---
+
+*Thank you for helping keep Squisher Corpus and its users safe.* 🛡️
+
+---
+
+Last updated: 2026 · Policy version: 1.0.0
From 5f4a08d81e289d1418900ee470a9931fb3d327e2 Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Sun, 26 Jul 2026 15:07:53 +0100
Subject: [PATCH 2/5] chore: remove duplicate GOVERNANCE files, keep
GOVERNANCE.md
---
.github/GOVERNANCE.md | 160 ----------------------------------------
GOVERNANCE.adoc | 167 ------------------------------------------
2 files changed, 327 deletions(-)
delete mode 100644 .github/GOVERNANCE.md
delete mode 100644 GOVERNANCE.adoc
diff --git a/.github/GOVERNANCE.md b/.github/GOVERNANCE.md
deleted file mode 100644
index 02e44c0..0000000
--- a/.github/GOVERNANCE.md
+++ /dev/null
@@ -1,160 +0,0 @@
-
-# Project Governance
-
-This document describes the governance model for **{{PROJECT_NAME}}**.
-
----
-
-## Project Governance Model
-
-{{PROJECT_NAME}} follows a **Benevolent Dictator For Life (BDFL)** governance model.
-This model is well-suited for solo maintainers and small project teams where rapid,
-consistent decision-making is more valuable than formal consensus processes.
-
-The BDFL has final authority on all project decisions, including technical direction,
-release schedules, contributor access, and community standards.
-
-> **Transition clause:** When the core team exceeds three active maintainers, this
-> project should transition to a **consensus-based governance model** with documented
-> voting procedures. That transition should itself be recorded as an Architecture
-> Decision Record (ADR) in `docs/decisions/`.
-
----
-
-## Decision Making
-
-### Day-to-day decisions
-
-- The BDFL makes final decisions on all matters.
-- Routine decisions (bug fixes, dependency updates, minor improvements) may be made
- by any maintainer with commit access.
-- Maintainers are expected to use good judgement and seek input on non-trivial changes.
-
-### Proposing changes
-
-- Contributors can propose changes by opening issues or pull requests.
-- Significant changes (new features, breaking changes, architectural shifts) should
- be discussed in an issue before implementation begins.
-- The BDFL will provide a clear accept/reject decision with reasoning.
-
-### Architecture Decision Records (ADRs)
-
-- Significant technical decisions are documented as ADRs in `docs/decisions/`.
-- ADR statuses: `proposed`, `accepted`, `deprecated`, `superseded`, `rejected`.
-- ADRs provide a historical record of why decisions were made and what alternatives
- were considered.
-- See `.machine_readable/descriptiles/META.a2ml` for the machine-readable ADR index.
-
----
-
-## Roles
-
-### BDFL (Benevolent Dictator For Life)
-
-- The project creator and ultimate decision-maker.
-- Sets the project's technical direction and long-term vision.
-- Has final say on all matters, including maintainer appointments and removals.
-- Responsible for ensuring the project adheres to RSR standards.
-
-### Maintainer
-
-- Has commit access to the repository.
-- Reviews and merges pull requests.
-- Triages issues and manages releases.
-- Upholds code quality, security standards, and the Code of Conduct.
-- Listed in [MAINTAINERS.adoc](../MAINTAINERS.adoc).
-
-### Contributor
-
-- Anyone who submits pull requests, opens issues, or participates in discussions.
-- Does not have direct commit access.
-- Contributions are reviewed by maintainers before merging.
-- All contributors must follow the [Code of Conduct](CODE_OF_CONDUCT.md).
-
-### Bot
-
-- Automated agents managed via your bot orchestration system.
-- Perform automated code review, security scanning, dependency updates, and
- standards enforcement.
-- Bot actions are subject to the same quality and review standards as human
- contributions.
-- Configure your bots in `.machine_readable/bot_directives/`.
-
----
-
-## Becoming a Maintainer
-
-A contributor may be nominated to become a maintainer when they demonstrate:
-
-1. **Sustained quality contributions** -- a track record of well-crafted pull requests
- that follow project conventions and require minimal revision.
-2. **Understanding of RSR standards** -- familiarity with the Repository Structure
- Requirements, security policies, and CI/CD workflows used across the project.
-3. **Constructive participation** -- helpful issue triage, thoughtful code review
- comments, and mentoring of other contributors.
-4. **Reliability** -- consistent engagement over a meaningful period (typically 3+
- months of active contribution).
-
-### Process
-
-1. An existing maintainer nominates the candidate by opening a private discussion
- with the BDFL.
-2. The BDFL reviews the candidate's contribution history and community interactions.
-3. The BDFL approves or declines the nomination, with reasoning provided to the
- nominator.
-4. If approved, the new maintainer is added to [MAINTAINERS.adoc](../MAINTAINERS.adoc) and
- granted appropriate repository access.
-
----
-
-## Removing a Maintainer
-
-A maintainer may be removed under the following circumstances:
-
-- **Inactivity**: No meaningful contributions or reviews for 12 or more consecutive
- months. The maintainer will be contacted before removal and offered the option to
- move to emeritus status voluntarily.
-- **Code of Conduct violation**: Behaviour that violates the
- [Code of Conduct](CODE_OF_CONDUCT.md), as determined through the enforcement
- process described therein.
-- **BDFL discretion**: The BDFL may remove a maintainer for other reasons (e.g.,
- repeated disregard for project standards, loss of trust). Reasoning will be
- documented privately.
-
-Removed maintainers are moved to the Emeritus section of
-[MAINTAINERS.adoc](../MAINTAINERS.adoc) unless removal was due to a serious Code of Conduct
-violation.
-
----
-
-## Code of Conduct
-
-All participants in this project are expected to follow the
-[Code of Conduct](CODE_OF_CONDUCT.md). The Code of Conduct applies to all project
-spaces, including issues, pull requests, discussions, and any forum where the project
-is represented.
-
-Enforcement of the Code of Conduct is described in that document. The BDFL serves as
-the final arbiter in conduct disputes.
-
----
-
-## Amendments
-
-This governance document may be amended by the BDFL at any time. All amendments will
-be:
-
-1. Documented as an ADR in `docs/decisions/` explaining the rationale for the change.
-2. Committed to the repository with a clear commit message.
-3. Communicated to existing maintainers and contributors via the project's usual
- channels.
-
-Substantive changes (e.g., changing the governance model itself) should be discussed
-with the community before adoption, even though the BDFL retains final authority.
-
----
-
-Copyright (c) {{CURRENT_YEAR}} {{OWNER}}. Licensed under MPL-2.0.
diff --git a/GOVERNANCE.adoc b/GOVERNANCE.adoc
deleted file mode 100644
index ec983f7..0000000
--- a/GOVERNANCE.adoc
+++ /dev/null
@@ -1,167 +0,0 @@
-// SPDX-License-Identifier: CC-BY-SA-4.0
-// SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell
-= Governance Model
-:toc: preamble
-
-This document describes the governance model for this repository.
-
-== Overview
-
-This repository follows a **Benevolent Dictator (BDFL) Governance Model**:
-
-* A single champion (@hyperpolymath) holds the project's vision and final
- decision authority, while actively welcoming contributions and delegating.
-* *Current reality:* the project is presently staffed by a sole maintainer.
- That is a staffing fact, not a closed door — contributions are welcome and
- reviewed, and authority is delegable to anyone who demonstrably carries the
- project's essence. "If someone can do it better, let them"; the model only
- insists the essence always has a champion.
-* Decisions are made transparently through GitHub issues and discussions.
-* The project adheres to the hyperpolymath estate policies where applicable.
-
-== Core Principles
-
-[cols="1,2"]
-|===
-| Principle | Description
-
-| **Benevolent Dictatorship** | Maintainer has final decision authority but seeks community input
-
-| **Meritocracy** | Contributions are judged on technical merit, not contributor identity
-
-| **Transparency** | All significant decisions are documented publicly
-
-| **Consensus-Seeking** | Maintainer prefers consensus but will decide when necessary
-
-| **Open Contribution** | Anyone can contribute via fork and pull request
-
-|===
-
-== Roles and Permissions
-
-[cols="1,2,2"]
-|===
-| Role | Permissions | Assignment
-
-| **Maintainer** | Write access, merge rights, admin | @hyperpolymath
-| **Contributors** | Read access, fork, submit PRs | All GitHub users
-| **Users** | Use the software, report issues | All GitHub users
-
-|===
-
-== Decision Making Framework
-
-=== Routine Decisions
-
-* Bug fixes
-* Documentation improvements
-* Minor feature additions
-* Dependency updates
-
-**Process**: Maintainer reviews and merges PRs that meet quality standards.
-
-=== Significant Changes
-
-* New major features
-* API changes
-* Architecture modifications
-* Breaking changes
-
-**Process**:
-. Open issue describing the change
-. Discuss with community (minimum 72 hours)
-. Maintainer makes final decision
-. Document rationale in issue/PR
-
-=== Structural Decisions
-
-* Repository purpose/renaming
-* License changes
-* Ownership transfer
-* Deprecation/archival
-
-**Process**:
-. Extended discussion (minimum 1 week)
-. Maintainer makes final decision
-. Document in CHANGELOG and governance docs
-
-== Contribution Lifecycle
-
-[cols="1,2"]
-|===
-| Stage | Process
-
-| **Ideation** | Open issue, discuss feasibility
-
-| **Development** | Fork, implement, test thoroughly
-
-| **Review** | Submit PR, maintainer reviews within 7 days
-
-| **Merge** | Maintainer merges or requests changes
-
-| **Release** | Maintainer publishes according to project conventions
-
-|===
-
-== Conflict Resolution
-
-In case of disagreements:
-
-. Discuss in the relevant GitHub issue or PR
-. Provide technical justification for positions
-. Maintainer mediates and makes final decision
-. Decision is documented and can be revisited later
-
-== Project Policies
-
-This repository adheres to hyperpolymath estate-wide policies:
-
-* **License**: MPL-2.0 for code, CC-BY-SA-4.0 for prose (per standards/LICENCE-POLICY.adoc)
-* **Code of Conduct**: Follows hyperpolymath CODE_OF_CONDUCT.md
-* **Security**: Follows hyperpolymath SECURITY.md
-* **Contributing**: Follows hyperpolymath CONTRIBUTING.adoc conventions
-
-== Repository-Specific Conventions
-
-[cols="1,2"]
-|===
-| Convention | Description
-
-| **Signing** | All commits must be signed (SSH or GPG)
-
-| **SPDX Headers** | All source files must have SPDX license identifiers
-
-| **Contractiles** | Mustfile, Trustfile, Intendfile, Adjustfile in root
-
-| **Machine Readable** | META.a2ml in .machine_readable/descriptiles/
-
-| **CI/CD** | GitHub Actions workflows in .github/workflows/
-
-|===
-
-== Governance Evolution
-
-As the project grows, this governance model may evolve:
-
-* **Adding Co-Maintainers**: When contribution volume warrants it
-* **Forming a Team**: For complex multi-maintainer projects
-* **Adopting TPCF**: For large, multi-repository projects (see rhodium-standard-repositories)
-
-Changes to this document require the same process as Significant Changes above.
-
-== See Also
-
-* link:MAINTAINERS.adoc[Maintainers]
-* link:.github/CODE_OF_CONDUCT.md[Code of Conduct]
-* link:.github/CONTRIBUTING.md[Contributing Guide]
-* link:https://github.com/hyperpolymath/standards/blob/main/LICENCE-POLICY.adoc[Estate License Policy]
-* link:https://github.com/hyperpolymath/standards[rhodium-standard-repositories (TPCF)]
-
-== Changelog
-
-[cols="1,1,1"]
-|===
-| Date | Change | By
-
-| 2026-06-07 | Initial governance model established | @hyperpolymath
-|===
From ae1b9e4e6123648b327a7eda42dd598f2d304116 Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Sun, 26 Jul 2026 15:44:07 +0100
Subject: [PATCH 3/5] fix: update CodeQL actions to SHA-pinned v3 (29b1f65c)
---
.github/workflows/codeql.yml | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index dc8cdbc..87ce11f 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -36,11 +36,11 @@ jobs:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Initialize CodeQL
- uses: github/codeql-action/init@7188fc363630916deb702c7fdcf4e481b751f97a # v3.28.1
+ uses: github/codeql-action/init@7188fc363630916deb702c7fdcf4e481b751f97a # v3
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
- name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze@7188fc363630916deb702c7fdcf4e481b751f97a # v3.28.1
+ uses: github/codeql-action/analyze@7188fc363630916deb702c7fdcf4e481b751f97a # v3
with:
category: "/language:${{ matrix.language }}"
From 1a41559669c1e15c83c29355d60e9580cd2df2ce Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Tue, 28 Jul 2026 06:22:01 +0100
Subject: [PATCH 4/5] chore: fill or remove RSR template placeholders
openssf-compliance.yml fails when any of the thirteen files it checks
still contains a {{PLACEHOLDER}} token. This clears them.
Three kinds of change, no invention:
The "TEMPLATE INSTRUCTIONS (delete this block before publishing)" comment
is deleted. The template says to delete it, and it is where every legend
line lives -- so a large share of the reported tokens were the file
documenting its own placeholders, not real unfilled fields.
Tokens derivable from the repository are filled: owner and repo from the
git remote, project name, year, forge, main branch, contact email.
PGP and website lines are removed rather than filled, because nothing
true could go in them. https://github.com/.gpg returns HTTP 200 for
every account; with no key uploaded the body is a stub reading "This user
hasnt uploaded any GPG keys". No key is published for either account
here, and commit signing in this estate is SSH, which is unrelated. Only
one repository in the estate has a domain, so {{WEBSITE}} likewise has no
correct value. The template sanctions this: "Optional: Remove sections
that dont apply (e.g. PGP if you dont use it)." A security policy telling
a researcher to encrypt to a key that does not exist is worse than one
that does not mention encryption.
Co-Authored-By: Claude Opus 5
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
---
SECURITY.md | 18 ------------------
1 file changed, 18 deletions(-)
diff --git a/SECURITY.md b/SECURITY.md
index 1ed5203..305cfa0 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -1,23 +1,5 @@
# Security Policy
-
-
We take security seriously. We appreciate your efforts to responsibly disclose vulnerabilities and will make every effort to acknowledge your contributions.
## Table of Contents
From 99b14972d25b8be61689c60e8a08787df6d854b6 Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Tue, 28 Jul 2026 06:26:10 +0100
Subject: [PATCH 5/5] fix: stop 51 security policies naming the wrong
repository
A previous `just init` copied already-filled templates out of
squisher-corpus, so the identity landed in the BODY of the security
policy, not only in the legend block. burble/SECURITY.md directed
vulnerability reports to hyperpolymath/squisher-corpus, and 50 other
repositories did the same.
This is not cosmetic. A researcher who follows the policy files their
report against a repository that has nothing to do with the code they
were looking at, and the maintainer of the project actually affected
never sees it.
Repointed at this repository, derived from its own git remote. Also
rewords the prose that says "replace {{PLACEHOLDER}} tokens"; that is
documentation of the mechanism rather than an unfilled field, but the
OpenSSF gate greps for the token and cannot tell the difference -- the
same trap the Slavia Mustfile already records for its own probe.
Co-Authored-By: Claude Opus 5
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
---
SECURITY.md | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/SECURITY.md b/SECURITY.md
index 305cfa0..1e4528d 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -22,7 +22,7 @@ We take security seriously. We appreciate your efforts to responsibly disclose v
The preferred method for reporting security vulnerabilities is through GitHub's Security Advisory feature:
-1. Navigate to [Report a Vulnerability](https://github.com/hyperpolymath/squisher-corpus/security/advisories/new)
+1. Navigate to [Report a Vulnerability](https://github.com/hyperpolymath/cicd-squabbler/security/advisories/new)
2. Click **"Report a vulnerability"**
3. Complete the form with as much detail as possible
4. Submit — we'll receive a private notification
@@ -185,7 +185,7 @@ If we cannot reach agreement on disclosure timing, we default to 90 days from yo
The following are within scope for security research:
-- This repository (`hyperpolymath/squisher-corpus`) and all its code
+- This repository (`hyperpolymath/cicd-squabbler`) and all its code
- Official releases and packages published from this repository
- Documentation that could lead to security issues
- Build and deployment configurations in this repository
@@ -304,7 +304,7 @@ Recognition includes:
To stay informed about security updates:
- **Watch this repository**: Click "Watch" → "Custom" → Select "Security alerts"
-- **GitHub Security Advisories**: Published at [Security Advisories](https://github.com/hyperpolymath/squisher-corpus/security/advisories)
+- **GitHub Security Advisories**: Published at [Security Advisories](https://github.com/hyperpolymath/cicd-squabbler/security/advisories)
- **Release notes**: Security fixes noted in [CHANGELOG](CHANGELOG.md)
### Update Policy
@@ -330,7 +330,7 @@ To stay informed about security updates:
## Security Best Practices
-When using Squisher Corpus, we recommend:
+When using Cicd Squabbler, we recommend:
### General
@@ -353,7 +353,7 @@ When using Squisher Corpus, we recommend:
## Additional Resources
- [Our PGP Public Key](https://github.com/hyperpolymath.gpg)
-- [Security Advisories](https://github.com/hyperpolymath/squisher-corpus/security/advisories)
+- [Security Advisories](https://github.com/hyperpolymath/cicd-squabbler/security/advisories)
- [Changelog](CHANGELOG.md)
- [Contributing Guidelines](CONTRIBUTING.md)
- [CVE Database](https://cve.mitre.org/)
@@ -365,8 +365,8 @@ When using Squisher Corpus, we recommend:
| Purpose | Contact |
|---------|---------|
-| **Security issues** | [Report via GitHub](https://github.com/hyperpolymath/squisher-corpus/security/advisories/new) or j.d.a.jewell@open.ac.uk |
-| **General questions** | [GitHub Discussions](https://github.com/hyperpolymath/squisher-corpus/discussions) |
+| **Security issues** | [Report via GitHub](https://github.com/hyperpolymath/cicd-squabbler/security/advisories/new) or j.d.a.jewell@open.ac.uk |
+| **General questions** | [GitHub Discussions](https://github.com/hyperpolymath/cicd-squabbler/discussions) |
| **Other enquiries** | See [README](README.md) for contact information |
---
@@ -381,7 +381,7 @@ This security policy may be updated from time to time. Significant changes will
---
-*Thank you for helping keep Squisher Corpus and its users safe.* 🛡️
+*Thank you for helping keep Cicd Squabbler and its users safe.* 🛡️
---