Skip to content

Handbook: security findings are the support hero's remit - #20046

Merged
rafaeelaudibert merged 3 commits into
masterfrom
posthog/support-hero-security-findings
Sep 9, 2026
Merged

Handbook: security findings are the support hero's remit#20046
rafaeelaudibert merged 3 commits into
masterfrom
posthog/support-hero-security-findings

Conversation

@rafaeelaudibert

@rafaeelaudibert rafaeelaudibert commented Sep 9, 2026

Copy link
Copy Markdown
Member

Changes

  • Support hero page: security findings in code a team owns are now listed as a source of tickets, with a new Security findings section that says the support hero picks them up alongside the normal support workload, points at security.posthog.dev, and mentions the weekly per-team Slack post.
  • Company security page: a short Fixing vulnerabilities in our own code section that links to the support hero page.

Why

The handbook did not say who fixes security findings in our own code. We now have security.posthog.dev and a weekly post in each team's channel, and the team's support hero is the right owner, so the handbook should say so.

Checklist

  • I've read the docs and/or content style guides.
  • Words are spelled using American English
  • Use relative URLs for internal links
  • I've checked the pages added or changed in the Vercel preview build
  • If I moved a page, I added a redirect in vercel.json (n/a — no pages moved)

Created with PostHog from a Slack thread

Add security findings as a source of support hero work, and point both the support hero page and the company security page at security.posthog.dev plus the monthly per-team Slack post.

Generated-By: PostHog Desktop
Task-Id: 2a9c5669-408c-4621-9b97-b4b9d151ead4
@github-actions github-actions Bot added content PR only touches files under contents/ handbook labels Sep 9, 2026
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Deploy preview

Status Details Updated (UTC)
🟢 Ready View preview Sep 09, 2026 09:27PM

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Vale prose linter → found 15 errors, 36 warnings, 0 suggestions in your markdown

Full report → Copy the linter results into an LLM to batch-fix issues.

Linter being weird? Update the rules!

contents/handbook/company/security.md — 6 errors, 20 warnings, 0 suggestions
Line Severity Message Rule
7:130 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
19:158 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
25:5 warning 'Yubikeys' is a possible misspelling. PostHogBase.Spelling
27:68 warning 'Yubikeys' is a possible misspelling. PostHogBase.Spelling
27:122 warning 'Yubikeys' is a possible misspelling. PostHogBase.Spelling
31:98 warning 'ruleset' is a possible misspelling. PostHogBase.Spelling
33:4 warning 'Mobile device management (MDM)' heading should be in sentence case, and product names should be capitalized. PostHogBase.SentenceCase
72:5 warning 'PostHog's obligations as a Data Processor' heading should be in sentence case, and product names should be capitalized. PostHogBase.SentenceCase
76:90 warning Capitalize 'Product Analytics' for PostHog's product. Use 'product analytics' for the general industry concept. PostHogBase.ProductNames
80:87 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
81:46 warning 'DPAs' is a possible misspelling. PostHogBase.Spelling
81:95 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
81:166 warning 'DPAs' is a possible misspelling. PostHogBase.Spelling
82:377 warning 'SCCs' is a possible misspelling. PostHogBase.Spelling
83:89 warning 'Hiberly' is a possible misspelling. PostHogBase.Spelling
84:68 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
87:144 warning Use 'PostHog' instead of 'posthog'. Vale.Terms
89:4 warning 'CCPA' heading should be in sentence case, and product names should be capitalized. PostHogBase.SentenceCase
99:52 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
103:154 warning Use 'PostHog' instead of 'posthog'. Vale.Terms
109:57 warning 'pentesting' is a possible misspelling. PostHogBase.Spelling
109:95 warning 'Veria' is a possible misspelling. PostHogBase.Spelling
109:134 warning 'triaged' is a possible misspelling. PostHogBase.Spelling
109:287 warning Use 'PostHog' instead of 'posthog'. Vale.Terms
115:254 warning Use 'PostHog' instead of 'posthog'. Vale.Terms
140:103 warning 'OAuth' is a possible misspelling. PostHogBase.Spelling
contents/handbook/engineering/operations/support-hero.md — 9 errors, 16 warnings, 0 suggestions
Line Severity Message Rule
27:4 warning 'What do I do as Support Hero?' heading should be in sentence case, and product names should be capitalized. PostHogBase.SentenceCase
38:92 warning Use 'PostHog' instead of 'posthog'. Vale.Terms
42:119 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
46:126 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
50:200 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
63:75 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
69:5 warning 'Papercuts' is a possible misspelling. PostHogBase.Spelling
73:47 warning 'papercut' is a possible misspelling. PostHogBase.Spelling
74:34 warning 'papercut' is a possible misspelling. PostHogBase.Spelling
77:1 warning 'Papercuts' is a possible misspelling. PostHogBase.Spelling
83:27 warning 'pentesting' is a possible misspelling. PostHogBase.Spelling
83:65 warning 'Veria' is a possible misspelling. PostHogBase.Spelling
83:100 warning 'triaged' is a possible misspelling. PostHogBase.Spelling
83:262 warning Use 'PostHog' instead of 'posthog'. Vale.Terms
89:231 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
110:31 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
112:37 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
123:34 warning 'Greptile' is a possible misspelling. PostHogBase.Spelling
158:4 warning 'Tips for being a great Support Hero' heading should be in sentence case, and product names should be capitalized. PostHogBase.SentenceCase
164:44 warning Use 'PostHog' instead of 'posthog'. Vale.Terms
172:20 warning 'labrador' is a possible misspelling. PostHogBase.Spelling
175:21 warning 'labrador' is a possible misspelling. PostHogBase.Spelling
191:54 warning 'timeframe' is a possible misspelling. PostHogBase.Spelling
194:140 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash
213:103 error Hi, Andy here... use an en dash ( – ) with spaces. On Mac, holding down the Option and hyphen key will give you an en dash. PostHogBase.EnDash

rafaeelaudibert and others added 2 commits September 9, 2026 18:10
Generated-By: PostHog Desktop
Task-Id: 2a9c5669-408c-4621-9b97-b4b9d151ead4
Generated-By: PostHog Desktop
Task-Id: 2a9c5669-408c-4621-9b97-b4b9d151ead4
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Bundle report

Total JS (gzip)

8.86 MiB (no change)

Eager graph (modules shipped in each entrypoint's initial chunks)

Entrypoint Eager size Budget Modules
app 18.46 MiB (no change) report-only 2054
Largest modules in the app closure
Module Size
./src/data/mcp-tools.json 1116.6 KiB
css ./node_modules/.pnpm/css-loader@5.2.7_webpack@5.101.3/node_modules/css-loader/dist/cjs.js??ruleSet[1].rules[8].oneOf[1].use[1]!./node_modules/.pnpm/postcss-loader@4.3.0_postcss@8.5.6_webpack@5.101.3/node_modules/postcss-loader/dist/cjs.js??ruleSet[1].rules[8].oneOf[1].use[2]!./src/styles/global.css 761.0 KiB
./src/components/Stickers/Stickers.tsx 696.4 KiB
./node_modules/.pnpm/@radix-ui+react-icons@1.3.2_react@18.3.1/node_modules/@radix-ui/react-icons/dist/react-icons.esm.js 481.4 KiB
./node_modules/.pnpm/@posthog+brand@0.8.0_react@18.3.1/node_modules/@posthog/brand/dist/generated/hoggies/svg/x-ray.mjs 480.8 KiB
./node_modules/.pnpm/rehype-raw@7.0.0/node_modules/rehype-raw/lib/index.js + 29 modules 395.1 KiB
./node_modules/.pnpm/@posthog+brand@0.8.0_react@18.3.1/node_modules/@posthog/brand/dist/generated/hoggies/svg/im-the-driver.mjs 385.7 KiB
./src/hooks/useCustomers.tsx + 55 modules 370.0 KiB
./node_modules/.pnpm/@posthog+icons@0.36.6_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js 354.8 KiB
./node_modules/.pnpm/react-markdown@8.0.7_@types+react@16.14.66_react@18.3.1/node_modules/react-markdown/lib/react-markdown.js + 88 modules 351.4 KiB
./src/components/ProductComparisonTable/index.tsx + 126 modules 302.5 KiB
./node_modules/.pnpm/cloudinary-core@2.14.0_lodash@4.17.21/node_modules/cloudinary-core/cloudinary-core.js 281.9 KiB
./node_modules/.pnpm/@posthog+brand@0.8.0_react@18.3.1/node_modules/@posthog/brand/dist/generated/hoggies/svg/doll-house.mjs 281.7 KiB
./node_modules/.pnpm/@posthog+brand@0.8.0_react@18.3.1/node_modules/@posthog/brand/dist/generated/hoggies/svg/director.mjs 275.6 KiB
./src/components/SearchUI/index.tsx + 87 modules 273.0 KiB

Eager-graph budgets are report-only until a baseline is established. Sizes are gzip of public/**/*.js; eager size is webpack module source bytes for the modules actually shipped in the entrypoint's initial chunks (post-tree-shake).

@rafaeelaudibert
rafaeelaudibert marked this pull request as ready for review September 9, 2026 21:24
@rafaeelaudibert
rafaeelaudibert enabled auto-merge (squash) September 9, 2026 21:24
@rafaeelaudibert
rafaeelaudibert merged commit 8f622dd into master Sep 9, 2026
21 checks passed
@rafaeelaudibert
rafaeelaudibert deleted the posthog/support-hero-security-findings branch September 9, 2026 21:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

content PR only touches files under contents/ handbook

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants