Create SECURITY.md for security policy#22797
Open
stoyanovaantoaneta76-hash wants to merge 1 commit intoOpenAPITools:masterfrom
Open
Create SECURITY.md for security policy#22797stoyanovaantoaneta76-hash wants to merge 1 commit intoOpenAPITools:masterfrom
stoyanovaantoaneta76-hash wants to merge 1 commit intoOpenAPITools:masterfrom
Conversation
Added a security policy document outlining supported versions and vulnerability reporting.
Contributor
There was a problem hiding this comment.
2 issues found across 1 file
Prompt for AI agents (all issues)
Check if these issues are valid — if so, understand the root cause of each and fix them.
<file name="SECURITY.md">
<violation number="1" location="SECURITY.md:10">
P2: SECURITY.md still contains a template Supported Versions table (5.1.x/5.0.x/4.0.x) that conflicts with the project’s documented 7.x/6.x releases, so the security policy does not reflect actual supported versions.</violation>
<violation number="2" location="SECURITY.md:17">
P2: Reporting instructions are still placeholder template text, so the security policy lacks any real vulnerability reporting process.</violation>
</file>
Since this is your first cubic review, here's how it works:
- cubic automatically reviews your code and comments on bugs and improvements
- Teach cubic by replying to its comments. cubic learns from your replies and gets better over time
- Ask questions if you need clarification on any suggestion
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.
|
|
||
| ## Reporting a Vulnerability | ||
|
|
||
| Use this section to tell people how to report a vulnerability. |
Contributor
There was a problem hiding this comment.
P2: Reporting instructions are still placeholder template text, so the security policy lacks any real vulnerability reporting process.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At SECURITY.md, line 17:
<comment>Reporting instructions are still placeholder template text, so the security policy lacks any real vulnerability reporting process.</comment>
<file context>
@@ -0,0 +1,21 @@
+
+## Reporting a Vulnerability
+
+Use this section to tell people how to report a vulnerability.
+
+Tell them where to go, how often they can expect to get an update on a
</file context>
|
|
||
| | Version | Supported | | ||
| | ------- | ------------------ | | ||
| | 5.1.x | :white_check_mark: | |
Contributor
There was a problem hiding this comment.
P2: SECURITY.md still contains a template Supported Versions table (5.1.x/5.0.x/4.0.x) that conflicts with the project’s documented 7.x/6.x releases, so the security policy does not reflect actual supported versions.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At SECURITY.md, line 10:
<comment>SECURITY.md still contains a template Supported Versions table (5.1.x/5.0.x/4.0.x) that conflicts with the project’s documented 7.x/6.x releases, so the security policy does not reflect actual supported versions.</comment>
<file context>
@@ -0,0 +1,21 @@
+
+| Version | Supported |
+| ------- | ------------------ |
+| 5.1.x | :white_check_mark: |
+| 5.0.x | :x: |
+| 4.0.x | :white_check_mark: |
</file context>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Addeda security policy document outlining supported versions and vulnerability reporting.PR checklist
Commit all changed files.
This is important, as CI jobs will verify all generator outputs of your HEAD commit as it would merge with master.
These must match the expectations made by your contribution.
You may regenerate an individual generator by passing the relevant config(s) as an argument to the script, for example
./bin/generate-samples.sh bin/configs/java*.IMPORTANT: Do NOT purge/delete any folders/files (e.g. tests) when regenerating the samples as manually written tests may be removed.
master(upcoming7.x.0minor release - breaking changes with fallbacks),8.0.x(breaking changes without fallbacks)"fixes #123"present in the PR description)Summary by cubic
Add SECURITY.md with a supported versions table and a section for reporting vulnerabilities. Supports 5.1.x and 4.0.x; 5.0.x and <4.0 are not supported.
Written for commit df3e1fb. Summary will update on new commits.