Skip to content

docs: use the org-wide security policy - #87

Merged
altaywtf merged 1 commit into
mainfrom
docs/drop-repo-security-policy
Oct 2, 2026
Merged

altaywtf merged 1 commit into
mainfrom
docs/drop-repo-security-policy

Conversation

@altaywtf

@altaywtf altaywtf commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Summary

rokit now defers to the put.io security policy instead of carrying its own copy.

Changed

  • Removes SECURITY.md and drops it from package.json files; the package-config test still guards AGENTS.md, docs, examples, and README.md.
  • README states the support window under Install and links the org policy; Distribution no longer mentions packaged security docs.
  • Device-secret hygiene already lives in Contributing and the bug report template; nothing else moved.

Risks

None beyond the tarball losing one doc file. docs: does not cut a release; the next release ships it.

Verification

pnpm run verify passed (165 tests); npm pack --dry-run lists 19 files, no SECURITY.md.


Written by an agent (Claude Code, Opus 5.5)

Drop the per-repo SECURITY.md in favor of putdotio/.github's policy and stop packaging it.
Copilot AI balanced review requested due to automatic review settings October 2, 2026 10:57
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

It is a small, self-consistent docs-only change with no dangling references and a verified-valid external policy link.

Review effort: Balanced
Findings: None

What changed in this PR

This PR removes rokit's own SECURITY.md and defers to the org-wide put.io security policy. It stops shipping the security doc in the npm tarball and updates the README link to the external policy, while preserving the "latest version receives routine fixes" support note by relocating it under Install.

Changes:

  • Deletes SECURITY.md and drops it from package.json files (and the corresponding assertion in test/package-config.test.ts).
  • Updates README.md to link the org-wide security policy and to state the support window under Install.
  • Adjusts docs/DISTRIBUTION.md wording to no longer claim the tarball ships security docs.
File Description
SECURITY.md Removes the repo-local security policy in favor of the org-wide one.
package.json Drops SECURITY.md from the packaged files list.
test/​package-config.test.ts Updates the packaged-files assertion to no longer expect SECURITY.md.
README.md Points the Security link to the org policy URL and adds the support-window note.
docs/​DISTRIBUTION.md Removes "security" from the description of what the tarball lets agents inspect.

I verified there are no remaining references to the local ./SECURITY.md, that the external org policy link target exists on main, and that the test assertion stays consistent with the updated package.json files.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@altaywtf
altaywtf merged commit 6cde179 into main Oct 2, 2026
7 checks passed
@altaywtf
altaywtf deleted the docs/drop-repo-security-policy branch October 2, 2026 11:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants