chore: add SECURITY-INSIGHTS.yml - #307
Open
gbartolini wants to merge 3 commits into
Open
Conversation
Modeled on cloudnative-pg/postgres-containers' file: a repository-scoped file pointing back to the main project.yaml/SECURITY-INSIGHTS.yml via header.project-si-source, with this repo's own core-team, license, release distribution points, and actual security tooling (verified against this repo's real CI workflows and repo settings, not copied blindly from another repo). Signed-off-by: Gabriele Bartolini <gabriele.bartolini@enterprisedb.com> Assisted-by: Claude
gbartolini
requested review from
GabriFedi97,
NiccoloFei,
armru,
fcanovai,
leonardoce and
mnencia
as code owners
August 4, 2026 02:00
Signed-off-by: Niccolò Fei <niccolo.fei@enterprisedb.com>
NiccoloFei
approved these changes
Aug 4, 2026
Signed-off-by: Niccolò Fei <niccolo.fei@enterprisedb.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a
SECURITY-INSIGHTS.ymlfor this repo, modeled on cloudnative-pg/postgres-containers's file: repository-scoped, pointing back to the main project's file viaheader.project-si-source, with this repo's own core-team (matchingcloudnative-pg/cnpg-infra'srepo-tiers.yamlowners), license, release distribution points, and security tooling — verified against this repo's actual CI workflows and repo settings rather than copied from another repo.Part of extending
SECURITY-INSIGHTS.ymlcoverage to every Class A repo (seecnpg-infra/repo-tiers.yaml), starting with this one.Assisted-by: Claude