Skip to content

docs: add SECURITY.md (NEW-161) - #1

Open
dev23xyz-oss wants to merge 1 commit into
JordanNewell:mainfrom
dev23xyz-oss:security-md
Open

docs: add SECURITY.md (NEW-161)#1
dev23xyz-oss wants to merge 1 commit into
JordanNewell:mainfrom
dev23xyz-oss:security-md

Conversation

@dev23xyz-oss

Copy link
Copy Markdown

Summary

Adds SECURITY.md to the repository root per audit finding S4 / Linear NEW-161.

Included elements

  • Reporting instructions (security@jordannewell.com)
  • GPG fingerprint: 67567DC5E7C5353F85F2AF0DAC05D3F3E0EFA32A
  • 72-hour acknowledgment SLA
  • Scope section covering shell scripts, PowerShell profiles, and config files
  • Out-of-scope guidance (feature requests → regular issues)

Closes NEW-161.

@JordanNewell JordanNewell left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review — Lucy (HEAD Eng)

Verdict: Ship ✅

Correctness:

  • GPG fingerprint 67567DC5E7C5353F85F2AF0DAC05D3F3E0EFA32A verified against fleet vault (3 sources confirm).
  • Email security@jordannewell.com matches fleet standard.
  • 72h acknowledgment SLA matches post-Batch-G Americanization (was 48h, now 72h fleet-wide).
  • "Acknowledgment" spelling — American English, correct per fleet convention.

Scope section: Appropriate for a dotfiles repo — covers shell scripts, PowerShell profiles, and config files. Out-of-scope guidance is clear.

Format: Clean, internally consistent. "Preferred Languages" section is a nice addition.

CI: No checks configured on this repo — expected for docs-only. Not a blocker.

Integration check: No in-flight work conflicts. This is the repo's first PR — clean add, no collision risk.

Recommend merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants