Skip to content

docs: add SECURITY.md, CONTRIBUTING.md, VERIFY.md - #174

Merged
Th0rgal merged 1 commit into
mainfrom
docs/security-contributing-verify
Feb 25, 2026
Merged

docs: add SECURITY.md, CONTRIBUTING.md, VERIFY.md#174
Th0rgal merged 1 commit into
mainfrom
docs/security-contributing-verify

Conversation

@Th0rgal

@Th0rgal Th0rgal commented Feb 25, 2026

Copy link
Copy Markdown
Owner

Summary

Test plan

  • All 634 tests pass (docs-only changes, no code modified)
  • Type-check clean for both desktop and generator tsconfigs
  • CI passes on this PR

Closes #163
Closes #164
Closes #169

🤖 Generated with Claude Code


Note

Low Risk
Docs-only changes (new policy/guides and README links) with no runtime or dependency impact; risk is limited to documentation accuracy.

Overview
Adds three new top-level docs: SECURITY.md (vulnerability reporting policy/scope), CONTRIBUTING.md (dev setup, test commands, PR expectations, security-sensitive areas), and VERIFY.md (how to verify release checksums and reproduce builds).

Updates README.md to link these new project docs, and updates AUDIT.md to mark the previously accepted Beacon API Zod-validation risk as fixed and reference the validating schemas/fetchBeaconJson typing change (from PR #173).

Written by Cursor Bugbot for commit efb5ce4. This will update automatically on new commits. Configure here.

- SECURITY.md: vulnerability reporting via GitHub Private Vulnerability
  Reporting, supported versions, response timeline, scope definition.
- CONTRIBUTING.md: dev setup, project structure, testing commands, PR
  expectations, and security-sensitive areas requiring extra review.
- VERIFY.md: checksum verification against SHA256SUMS.txt, build-from-
  source instructions for all platforms, reproducibility limitations.
- README.md: add project docs section linking the three new files.
- AUDIT.md: mark beacon API Zod validation as fixed (PR #173).

Closes #163
Closes #164
Closes #169

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@vercel

vercel Bot commented Feb 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
safe-lens-generator Building Building Preview, Comment Feb 25, 2026 3:51pm

Request Review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@Th0rgal
Th0rgal merged commit 83455d6 into main Feb 25, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant