Skip to content

docs: add SECURITY.md security policy (#336)#732

Merged
michalharakal merged 1 commit into
developfrom
chore/security-policy-336
Jun 10, 2026
Merged

docs: add SECURITY.md security policy (#336)#732
michalharakal merged 1 commit into
developfrom
chore/security-policy-336

Conversation

@michalharakal

Copy link
Copy Markdown
Contributor

What

Adds a standard SECURITY.md — the security-policy slice of OSS best practices, answering #336 ("S in SKaiNET is for security?").

Contents

  • Private vulnerability reporting via GitHub Security Advisories (no email/SLA invented)
  • Supported versions — latest release + develop (pre-1.0)
  • Scope — model I/O readers (GGUF/SafeTensors/ONNX) on untrusted files, and generated export artifacts (Minerva/StableHLO)
  • Pointer to the broader best-practices work tracked in [Feature]: Add Open Source Best Practises #594

The remaining OSS posture (REUSE/OpenSSF Best Practices badge, SBOM, dependency scanning) stays with #594.

Closes #336

🤖 Generated with Claude Code

Add a standard security policy: private vulnerability reporting via GitHub
Security Advisories, supported-version statement, and scope (model I/O readers,
export artifacts). The broader OSS best-practices posture (REUSE/OpenSSF/SBOM)
remains tracked by #594.

Closes #336

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@michalharakal michalharakal merged commit 6d85369 into develop Jun 10, 2026
4 checks passed
@michalharakal michalharakal deleted the chore/security-policy-336 branch June 10, 2026 16:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

S in SKaiNET is for security ?

1 participant