Skip to content

feat(KONFLUX-15176): add SECURITY.md for CRA - #441

Open
nmars wants to merge 1 commit into
conforma:mainfrom
nmars:add-security-md-for-cra
Open

feat(KONFLUX-15176): add SECURITY.md for CRA#441
nmars wants to merge 1 commit into
conforma:mainfrom
nmars:add-security-md-for-cra

Conversation

@nmars

@nmars nmars commented Aug 26, 2026

Copy link
Copy Markdown

Summary

  • Add SECURITY.md to comply with CRA (EU Cyber Resilience Act) requirements.

Jira: KONFLUX-15176

Signed-off-by: Nate Marsella <nmarsell@redhat.com>
@qodo-for-conforma

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can start a comment with 'qodo' or '@qodo' to chat about any finding

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@coderabbitai

coderabbitai Bot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 83ffa27e-fa78-4f2a-8021-e4d3f2175f0b


Comment @coderabbitai help to get the list of available commands.

@qodo-for-conforma

Copy link
Copy Markdown

PR Summary by Qodo

Add CRA-compliant security reporting guidance

📝 Documentation 🕐 Less than 5 minutes

Grey Divider

AI Description

• Adds a repository security vulnerability and incident reporting entry point.
• Directs reporters to Conforma’s centralized security policy for CRA compliance.
High-Level Assessment

A short repository-level SECURITY.md linking to the centrally maintained Conforma policy is the appropriate approach. It provides GitHub’s expected discovery point while avoiding duplicated reporting instructions that could drift across repositories.

Files changed (1) +5 / -0

Documentation (1) +5 / -0
SECURITY.mdAdd centralized security reporting guidance +5/-0

Add centralized security reporting guidance

• Adds the repository’s security vulnerability and incident reporting entry point. The document links to Conforma’s organization-wide security policy to support CRA compliance and centralized maintenance.

SECURITY.md

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant