added SECURITY.md#34
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✅ Files skipped from review due to trivial changes (1)
📝 WalkthroughWalkthroughA SECURITY.md file is added describing supported-release handling (pre-release, fixes on latest develop until v0.1.0 tag), a private vulnerability reporting path (GitHub or will@cppalliance.org with optional PGP/secure channel), required report contents, acknowledgement/resolution timelines, and in-scope/out-of-scope vulnerability categories. ChangesSecurity Policy Addition
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Tip 💬 Introducing Slack Agent: The best way for teams to turn conversations into code.Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.
Built for teams:
One agent for your entire SDLC. Right inside Slack. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
- Replace semver-style Supported Versions table with pre-release develop-branch note (no tags yet) - Add encrypted-channel / PGP fingerprint offer for email reporters - Document CVE coordination via GitHub CNA and reporter credit - Clarify out-of-scope resource exhaustion vs privilege/exfil scenarios Co-authored-by: Cursor <cursoragent@cursor.com>
close #30
Summary by CodeRabbit