docs: add SECURITY.md - #61
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
The new policy text contains a couple of potentially misleading/unverifiable statements (CVE “request” guarantee wording, Dependabot handling claim) that should be tightened for accuracy.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Adds a repository-level SECURITY.md security policy for the Cloudflare Workers user-management framework, documenting private vulnerability reporting, response expectations for a solo maintainer, supported-version stance for a fork-and-deploy model, scope boundaries, and the project’s SHA-256 password-hashing constraint.
Changes:
- Introduces guidance for privately reporting vulnerabilities via GitHub Security Advisories.
- Defines response-time expectations, supported versions, and in-scope/out-of-scope vulnerability categories.
- Documents known design constraints around password hashing choices in Workers.
File summaries
| File | Description |
|---|---|
| SECURITY.md | Adds a security policy covering reporting, expectations, supported versions, scope, and design constraints. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| Confirmed vulnerabilities get a published GitHub security advisory with a | ||
| CVE request, credit to the reporter, and a tagged release containing the | ||
| fix. If you prefer not to be credited, say so in the report. |
| - Vulnerabilities in dependencies (report upstream; dependency bumps here | ||
| are handled via Dependabot) |
Adds a security policy: private reporting via GitHub advisories, realistic solo-maintainer response times, supported-versions table reflecting the fork-and-deploy model, scope, and the SHA-256 design constraint.
https://claude.ai/code/session_011sL8MCm9Qma4oKkvdZbHu5