Skip to content

docs(security): cross-link ADR-0042 sandbox policy from SECURITY.md#2

Merged
anthonyadame merged 1 commit into
mainfrom
docs/security-adr-0042-crosslink
May 14, 2026
Merged

docs(security): cross-link ADR-0042 sandbox policy from SECURITY.md#2
anthonyadame merged 1 commit into
mainfrom
docs/security-adr-0042-crosslink

Conversation

@anthonyadame
Copy link
Copy Markdown
Contributor

Summary

Single-line addition to the What IS in scope section pointing vulnerability reporters at the org-canonical sandbox / host-execution policy:

ADR-0042: Sandbox Bypass Policy

kaizen-cli ships the Python pipeline that exercises the sandbox in production. Host-execution semantics are the most code-execution-relevant policy area, so the in-scope section is the natural home for the cross-link.

Part 2/4 of roadmap item 60.11 (SECURITY.md cross-link to ADR-0042 across kaizen-staging / kaizen-cli / benchmarks / kaizen-3c-web).

Test plan

  • grep -n 'ADR-0042' SECURITY.md → match in the in-scope section
  • DCO sign-off on commit

Single-line addition to the "What IS in scope" section pointing
disclosure reporters at the org-canonical sandbox / host-execution
policy:

  https://github.com/Kaizen-3C/kaizen-staging/blob/main/.architecture/decisions/ADR-0042-sandbox-bypass-policy.md

The kaizen-cli ships the Python pipeline that exercises the sandbox
in production; host-execution semantics are the most code-execution-
relevant policy area, so the in-scope section is the natural home
for the cross-link.

Part 2/4 of roadmap item 60.11 (SECURITY.md cross-link to ADR-0042
across kaizen-staging / kaizen-cli / benchmarks / kaizen-3c-web).

Signed-off-by: anthonyadame <anthonyadame@gmail.com>
@anthonyadame anthonyadame merged commit 0c4a4a9 into main May 14, 2026
4 checks passed
@anthonyadame anthonyadame deleted the docs/security-adr-0042-crosslink branch May 14, 2026 20:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant