Skip to content

chore: clarify disclosure policy#10890

Merged
jasonsaayman merged 1 commit into
v1.xfrom
docs/clarify-sec-fix-releases
May 13, 2026
Merged

chore: clarify disclosure policy#10890
jasonsaayman merged 1 commit into
v1.xfrom
docs/clarify-sec-fix-releases

Conversation

@jasonsaayman

@jasonsaayman jasonsaayman commented May 13, 2026

Copy link
Copy Markdown
Member

Summary by cubic

Clarifies the security disclosure policy in SECURITY.md: we will always publish advisories by day 60, prefer to ship fixes before advisories, and update advisories once patches are ready. Removes the milestone table to keep the policy concise and clear.

Description

  • Clarifies that advisories publish by day 60 even if a fix is not ready; advisory gets updated once the patch ships.
  • States we prefer releasing the fix before the advisory, but will not delay the advisory past day 60.
  • Removes the day-by-day milestone table to reduce noise and ambiguity.
  • Reasoning: align docs with actual process and set clear expectations for reporters and users.

Docs

  • Mirror these changes on the docs site in /docs/ (e.g., the security policy page) to match the updated SECURITY.md.

Testing

  • No tests needed; docs-only change.

Semantic version impact

  • Patch (docs-only).

Written for commit abcc594. Summary will update on new commits.

@jasonsaayman jasonsaayman self-assigned this May 13, 2026
@jasonsaayman jasonsaayman added priority::medium A medium priority commit::docs The PR is related to docs labels May 13, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

@jasonsaayman jasonsaayman merged commit 363fc48 into v1.x May 13, 2026
25 checks passed
@jasonsaayman jasonsaayman deleted the docs/clarify-sec-fix-releases branch May 13, 2026 17:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

commit::docs The PR is related to docs priority::medium A medium priority

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant