Skip to content

Update security policy for CRA - #84

Merged
joejstuart merged 1 commit into
conforma:mainfrom
nmars:update-securitymd-for-cra
Aug 25, 2026
Merged

Update security policy for CRA#84
joejstuart merged 1 commit into
conforma:mainfrom
nmars:update-securitymd-for-cra

Conversation

@nmars

@nmars nmars commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Updated security policy for EU Cyber Resilience Act (CRA).

GitHub will render this as the default security policy for all repositories under the conforma org.

For: KONFLUX-15176

@coderabbitai

coderabbitai Bot commented Aug 24, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: a13d9a9e-685c-433d-872d-8e509451b904


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-for-conforma

Copy link
Copy Markdown

PR Summary by Qodo

Document CRA security reporting and stewardship policy

📝 Documentation 🕐 Less than 5 minutes

Grey Divider

AI Description

• Clarifies Conforma’s private vulnerability reporting and response timeline.
• Links Red Hat’s coordinated disclosure and vulnerability management policies.
• Declares Red Hat’s open source steward role under the EU CRA.
High-Level Assessment

A repository-level SECURITY.md is the appropriate GitHub-native mechanism for publishing the organization’s default reporting and CRA stewardship policy. Separate documentation or external-only guidance would be less discoverable to vulnerability reporters.

Files changed (1) +18 / -5

Documentation (1) +18 / -5
SECURITY.mdAdd CRA stewardship and expanded security reporting guidance +18/-5

Add CRA stewardship and expanded security reporting guidance

• Reorganizes vulnerability reporting guidance, fixes the private-reporting instructions link, and gives the three-working-day response commitment its own section. Adds Red Hat disclosure resources, the EU Cyber Resilience Act steward statement, and a dedicated CRA contact address.

SECURITY.md

@qodo-for-conforma

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can switch off images and animations for a plain-text comment

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread SECURITY.md

@simonbaird simonbaird left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lgtm.

@joejstuart
joejstuart merged commit ecbc09d into conforma:main Aug 25, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants