Skip to content

feat(KONFLUX-15176): add SECURITY.md for CRA - #1019

Merged
mshaposhnik merged 2 commits into
konflux-ci:mainfrom
nmars:add-security-md-for-cra
Sep 3, 2026
Merged

feat(KONFLUX-15176): add SECURITY.md for CRA#1019
mshaposhnik merged 2 commits into
konflux-ci:mainfrom
nmars:add-security-md-for-cra

Conversation

@nmars

@nmars nmars commented Aug 25, 2026

Copy link
Copy Markdown
Member

Summary

  • Add SECURITY.md to comply with CRA (EU Cyber Resilience Act) requirements.

Jira: KONFLUX-15176

Signed-off-by: Nate Marsella <nmarsell@redhat.com>
@qodo-app-for-konflux-ci

qodo-app-for-konflux-ci Bot commented Aug 25, 2026

Copy link
Copy Markdown

PR Summary by Qodo

Add CRA-compliant security reporting guidance

📝 Documentation 🕐 Less than 5 minutes

Grey Divider

AI Description

• Adds repository security reporting guidance to support CRA compliance.
• Directs vulnerability and incident reports to organization-wide Konflux instructions.
High-Level Assessment

The centralized-link approach is optimal because it satisfies repository-level disclosure requirements while avoiding duplicated security procedures that could drift from organization-wide guidance.

Files changed (1) +5 / -0

Documentation (1) +5 / -0
SECURITY.mdAdd centralized security vulnerability reporting guidance +5/-0

Add centralized security vulnerability reporting guidance

• Introduces repository-level instructions for reporting Konflux security vulnerabilities or incidents. The document links to the organization-wide security policy to support CRA compliance.

SECURITY.md

@qodo-app-for-konflux-ci

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can hide the parts of a finding you never read, like the evidence or the agent prompt

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 25, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 6:07 PM UTC · Completed 6:15 PM UTC

Commit: 9ee3c25 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.39

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 25, 2026

Copy link
Copy Markdown

Looks good to me

Previous run

Looks good to me

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Aug 25, 2026
@qodo-app-for-konflux-ci

qodo-app-for-konflux-ci Bot commented Sep 2, 2026

Copy link
Copy Markdown

No code changes since the last review — review skipped

Qodo Logo

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 2, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 12:43 PM UTC · Completed 12:53 PM UTC

Commit: 9ee3c25 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.90

@fullsend-ai-review fullsend-ai-review Bot added the risk/low PR risk: low label Sep 2, 2026
@fullsend-ai-review

Copy link
Copy Markdown

Risk Assessment: low (1/5)

Details

Single new documentation file (SECURITY.md) with 5 lines added for CRA compliance, submitted by established contributor, no protected paths or dependencies touched.

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 77.31%. Comparing base (d3e3319) to head (9e6f70c).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #1019      +/-   ##
==========================================
+ Coverage   76.92%   77.31%   +0.39%     
==========================================
  Files          26       26              
  Lines        2817     2817              
==========================================
+ Hits         2167     2178      +11     
+ Misses        452      445       -7     
+ Partials      198      194       -4     
Flag Coverage Δ
unit-tests 73.98% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.
see 3 files with indirect coverage changes


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update d3e3319...9e6f70c. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@mshaposhnik
mshaposhnik disabled auto-merge September 3, 2026 16:43
@mshaposhnik
mshaposhnik merged commit 61379a1 into konflux-ci:main Sep 3, 2026
21 of 22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-for-merge All reviewers approved — ready to merge risk/low PR risk: low

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants