docs: use the org-wide security policy - #87
Conversation
Drop the per-repo SECURITY.md in favor of putdotio/.github's policy and stop packaging it.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
It is a small, self-consistent docs-only change with no dangling references and a verified-valid external policy link.
Review effort: Balanced
Findings: None
What changed in this PR
This PR removes rokit's own SECURITY.md and defers to the org-wide put.io security policy. It stops shipping the security doc in the npm tarball and updates the README link to the external policy, while preserving the "latest version receives routine fixes" support note by relocating it under Install.
Changes:
- Deletes
SECURITY.mdand drops it frompackage.jsonfiles(and the corresponding assertion intest/package-config.test.ts). - Updates
README.mdto link the org-wide security policy and to state the support window under Install. - Adjusts
docs/DISTRIBUTION.mdwording to no longer claim the tarball ships security docs.
| File | Description |
|---|---|
SECURITY.md |
Removes the repo-local security policy in favor of the org-wide one. |
package.json |
Drops SECURITY.md from the packaged files list. |
test/package-config.test.ts |
Updates the packaged-files assertion to no longer expect SECURITY.md. |
README.md |
Points the Security link to the org policy URL and adds the support-window note. |
docs/DISTRIBUTION.md |
Removes "security" from the description of what the tarball lets agents inspect. |
I verified there are no remaining references to the local ./SECURITY.md, that the external org policy link target exists on main, and that the test assertion stays consistent with the updated package.json files.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Summary
rokit now defers to the put.io security policy instead of carrying its own copy.
Changed
SECURITY.mdand drops it frompackage.jsonfiles; the package-config test still guardsAGENTS.md,docs,examples, andREADME.md.Risks
None beyond the tarball losing one doc file.
docs:does not cut a release; the next release ships it.Verification
pnpm run verifypassed (165 tests);npm pack --dry-runlists 19 files, noSECURITY.md.Written by an agent (Claude Code, Opus 5.5)