Skip to content

NO_JIRA chore: Add .github/SECURITY.md - #1112

Open
gundalow wants to merge 1 commit into
ansible:develfrom
gundalow:rollout/add-security-md
Open

NO_JIRA chore: Add .github/SECURITY.md#1112
gundalow wants to merge 1 commit into
ansible:develfrom
gundalow:rollout/add-security-md

Conversation

@gundalow

@gundalow gundalow commented Aug 25, 2026

Copy link
Copy Markdown

Summary

Add a standardised SECURITY.md to .github/ so security reporting instructions are discoverable across all Ansible repositories.

The canonical source is ansible-community/project-template/SECURITY.md.

The file has already been reviewed

See Forum Post for context

Summary by CodeRabbit

  • Documentation
    • Expanded the security policy with private vulnerability reporting guidance.
    • Added required report details and response timelines.
    • Documented backport handling and related security responsibilities.
    • Added statements covering the Ansible Security Policy and EU Cyber Resilience Act stewardship.

@gundalow
gundalow enabled auto-merge (squash) August 25, 2026 18:29
@coderabbitai

coderabbitai Bot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a6fd250-cc0f-4201-b089-c379f0b9b4f0

📥 Commits

Reviewing files that changed from the base of the PR and between 5d64aaf and 68017a2.

📒 Files selected for processing (1)
  • SECURITY.md

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

SECURITY.md now documents private vulnerability reporting, report contents, response targets, backport handling, the Ansible Security Policy, and Red Hat’s EU Cyber Resilience Act stewardship.

Changes

Security policy documentation

Layer / File(s) Summary
Security reporting and stewardship guidance
SECURITY.md
Adds email-based vulnerability reporting instructions, public disclosure restrictions, required and optional report details, response targets, security-update backport policy, an Ansible Security Policy link, and CRA steward contact information.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to 68017

This documentation-only change adds security reporting guidance without introducing an actionable merge-blocking risk; it is merge-ready after normal checks and review.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the addition of .github/SECURITY.md, which is the main change.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@gundalow gundalow changed the title chore: Add .github/SECURITY.md AAP-0000 chore: Add .github/SECURITY.md Aug 25, 2026
@gundalow gundalow changed the title AAP-0000 chore: Add .github/SECURITY.md AAP-00000 chore: Add .github/SECURITY.md Aug 25, 2026
@codecov

codecov Bot commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 94.77%. Comparing base (5d64aaf) to head (68017a2).

@@           Coverage Diff           @@
##            devel    #1112   +/-   ##
=======================================
  Coverage   94.77%   94.77%           
=======================================
  Files         259      259           
  Lines       14485    14485           
  Branches     2218     2218           
=======================================
  Hits        13728    13728           
  Misses        757      757           
Flag Coverage Δ
py312 94.73% <ø> (ø)
py312-sqlite 94.11% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 5d64aaf...68017a2. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown

DVCS PR Check Results:

Could not find JIRA key(s) in PR title, branch name, or commit messages

@gundalow gundalow changed the title AAP-00000 chore: Add .github/SECURITY.md NO_JIRA chore: Add .github/SECURITY.md Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant