Skip to content

Update security reporting policy - #579

Merged
vishnu-narayanan merged 1 commit into
mainfrom
codex/security-reporting-cve-policy-node22
Jul 28, 2026
Merged

Update security reporting policy#579
vishnu-narayanan merged 1 commit into
mainfrom
codex/security-reporting-cve-policy-node22

Conversation

@sony-mathew

Copy link
Copy Markdown
Contributor

Summary

  • Clarify security report quality expectations, duplicate handling, and canonical earliest-report policy.
  • Document when Chatwoot requests/publishes CVEs and when duplicate, theoretical, scanner-only, upstream dependency, or hardening-only items do not get new CVEs.
  • Pin docs Node version to 22.22.2 and make the broken-link workflow use .nvmrc via actions/setup-node.

Validation

  • git diff --check
  • nvm use v22.22.2 && node -v && npm -v
  • PUPPETEER_SKIP_DOWNLOAD=true npm_config_cache=/tmp/npm-cache-node-22-22-2 npx --yes mint@latest broken-links

@vishnu-narayanan
vishnu-narayanan merged commit 376277a into main Jul 28, 2026
1 check passed
@vishnu-narayanan
vishnu-narayanan deleted the codex/security-reporting-cve-policy-node22 branch July 28, 2026 07:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants