Skip to content

docs: add Action security policy and changelog - #11

Merged
attomus-gh merged 1 commit into
mainfrom
docs/action-security-changelog-2026-09-03
Sep 3, 2026
Merged

docs: add Action security policy and changelog#11
attomus-gh merged 1 commit into
mainfrom
docs/action-security-changelog-2026-09-03

Conversation

@attomus-gh

Copy link
Copy Markdown
Contributor

Summary

  • expand the responsible-disclosure policy with supported versions, scope, and the live Attomus response commitment
  • add the release-ready v1.0.0 changelog and README pointer
  • refresh two dev-only transitive locks to clear newly disclosed high-severity advisories
  • enable private vulnerability reporting for the repository so the documented Security-tab route works

Verification

  • npm run verify (23 tests; audit clean)
  • gitleaks detect --no-banner -v (17 commits; no leaks)
  • git diff --check
  • prohibited-string sweep clean
  • npm ls @attomus/semafore-crypto fast-uri nanoid --all resolves crypto 1.0.1, fast-uri 3.1.7, and nanoid 3.3.18
  • https://attomus.com/security/ returns HTTP 200 and states 48-hour acknowledgement / 7-day initial assessment

Release gate

  • documentation-only public behavior; no Action runtime or wire-contract change
  • sf-test-harness impact reviewed: none
  • v1.0.0 remains marked Unreleased until the tag phase records the actual release date

@attomus-gh
attomus-gh merged commit 0789bea into main Sep 3, 2026
1 check passed
@attomus-gh
attomus-gh deleted the docs/action-security-changelog-2026-09-03 branch September 3, 2026 17:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant