Skip to content

docs: add SECURITY.md - #420

Merged
VickyXAI merged 1 commit into
mainfrom
docs/security-policy
Oct 5, 2026
Merged

VickyXAI merged 1 commit into
mainfrom
docs/security-policy

Conversation

@VickyXAI

@VickyXAI VickyXAI commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Adds a security policy matching Franklin's: private reporting via GitHub advisories (or hello@blockrun.ai), 48h acknowledgement, credit in advisories and release notes, no paid bounty.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Documentation
    • Added a security policy explaining how to report vulnerabilities privately, what details to include, and when to expect acknowledgement and assessment.
    • Clarified how security fixes and advisories are handled, including that fixes apply to the latest npm release and reporters may receive credit.
    • Listed the components covered by the policy and the types of reports considered out of scope.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: BlockRunAI/ClawRouter/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d4dd8405-1745-42cf-9117-0e0a076ef454
📥 Commits

Reviewing files that changed from the base of the PR and between 14d20ac and 6907150.

📒 Files selected for processing (1)
  • SECURITY.md

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

SECURITY.md adds ClawRouter’s security policy. It describes private vulnerability reporting, response timelines, security fixes, reporter credit, and the scope of reports.

Changes

Security Policy

Layer / File(s) Summary
Reporting and handling policy
SECURITY.md
Adds private reporting channels and report details, response timelines, fix and disclosure practices, reporter credit guidance, and in-scope and out-of-scope topics.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 69071

The policy adds private vulnerability-reporting guidance consistent with the checked-in project identity, with no established conflict in the release guidance.

Architecture Summary

Architecture risk: 🔵 Low · up to 69071

The change affects 1 system.

Changed systems: SECURITY.md

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — SECURITY.md (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in SECURITY.md: Adds private vulnerability-reporting channels, a warning against public disclosure, and a list of useful report details.
  • observed — Modified behavior in SECURITY.md: Adds acknowledgement and assessment timelines and describes private-fork fixes, patch releases, and advisory publication after the fixed version is on npm.
  • observed — Modified behavior in SECURITY.md: States that only the latest npm release receives security fixes and describes reporter credit and anonymity.
  • observed — Modified behavior in SECURITY.md: Defines ClawRouter components and security topics in scope, and excludes third-party vulnerabilities, social engineering, and denial of service requiring local machine access.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the addition of SECURITY.md, which is the main change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@VickyXAI
VickyXAI merged commit b758e03 into main Oct 5, 2026
5 checks passed
@VickyXAI
VickyXAI deleted the docs/security-policy branch October 5, 2026 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant