Skip to content

feat(KONFLUX-15176): add SECURITY.md for CRA - #3520

Open
nmars wants to merge 1 commit into
conforma:mainfrom
nmars:add-security-md-for-cra
Open

feat(KONFLUX-15176): add SECURITY.md for CRA#3520
nmars wants to merge 1 commit into
conforma:mainfrom
nmars:add-security-md-for-cra

Conversation

@nmars

@nmars nmars commented Aug 26, 2026

Copy link
Copy Markdown

Summary

  • Add SECURITY.md to comply with CRA (EU Cyber Resilience Act) requirements.

Jira: KONFLUX-15176

Signed-off-by: Nate Marsella <nmarsell@redhat.com>
@coderabbitai

coderabbitai Bot commented Aug 26, 2026

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 921fea77-2f69-4eaa-a69a-2054da09afc3

📥 Commits

Reviewing files that changed from the base of the PR and between f712ec1 and bfd9a63.

📒 Files selected for processing (1)
  • SECURITY.md

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Added SECURITY.md with instructions for reporting Conforma security vulnerabilities or incidents through the linked security policy.

Changes

Security guidance

Layer / File(s) Summary
Security policy reference
SECURITY.md
Adds security reporting instructions and links to the Conforma security policy.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Merge Risk: ⚪ Minimal · up to bfd9a

This change adds the project security policy and vulnerability-reporting process without introducing code or runtime behavior changes. No actionable merge-blocking risk remains after normal checks and review.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the addition of SECURITY.md and its CRA purpose. It includes the related ticket and uses a concise format.
Description check ✅ Passed The description states what changed, why it changed, and links the Jira ticket. It uses a Summary heading instead of the template's What, Why, and Tickets headings, but it provides the required inform…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description states what changed, why it changed, and links the Jira ticket. It uses a Summary heading instead of the template's What, Why, and Tickets headings, but it provides the required information.

Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@qodo-for-conforma

Copy link
Copy Markdown

PR Summary by Qodo

Add CRA security reporting guidance

📝 Documentation 🕐 Less than 5 minutes

Grey Divider

AI Description

• Adds a repository security policy for CRA compliance.
• Directs vulnerability and incident reports to Conforma’s centralized security guidance.
High-Level Assessment

A short repository-level SECURITY.md linking to the organization-maintained policy is the appropriate approach because it satisfies repository discoverability requirements while avoiding duplicated security instructions that could drift.

Files changed (1) +5 / -0

Documentation (1) +5 / -0
SECURITY.mdAdd centralized security reporting guidance +5/-0

Add centralized security reporting guidance

• Adds a repository security policy directing vulnerability and incident reporters to Conforma’s centrally maintained instructions. This supports EU Cyber Resilience Act compliance without duplicating organization-wide guidance.

SECURITY.md

@qodo-for-conforma

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (1) 📜 Skill insights (0)

Grey Divider


Remediation recommended

1. Conforma uses wrong product name 📘 Rule violation § Compliance
Description
The new user-facing security documentation names the product Conforma instead of the required
Conforma CLI. This creates inconsistent product naming in public documentation.
Code

SECURITY.md[1]

+# Reporting a Security Vulnerability or Incident for Conforma
Relevance

●●● Strong

Exact product-name compliance is a deterministic documentation fix; historical documentation
corrections are consistently accepted.

PR-#3044
PR-#3021

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
PR Compliance ID 3784 requires product-name references in newly added user-facing documentation to
use exactly Conforma CLI; the added heading instead says for Conforma.

Rule 3784: Use the product name "Conforma CLI" in new user-facing text
SECURITY.md[1-1]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The new security-document heading uses `Conforma` instead of the required product name `Conforma CLI`.

## Issue Context
PR Compliance ID 3784 requires new user-facing documentation to use exactly `Conforma CLI` for product-name references.

## Fix Focus Areas
- SECURITY.md[1-1]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
⚠️ Tickets: not configured — ticket URL found in PR but could not be fetched — check ticket provider credentials
✅ Compliance rules (platform): 38 rules

Grey Divider

Tip of the day
💡 Did you know, you can start a comment with 'qodo' or '@qodo' to chat about any finding

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread SECURITY.md
@@ -0,0 +1,5 @@
# Reporting a Security Vulnerability or Incident for Conforma

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

1. conforma uses wrong product name 📘 Rule violation § Compliance

The new user-facing security documentation names the product Conforma instead of the required
Conforma CLI. This creates inconsistent product naming in public documentation.
Agent Prompt
## Issue description
The new security-document heading uses `Conforma` instead of the required product name `Conforma CLI`.

## Issue Context
PR Compliance ID 3784 requires new user-facing documentation to use exactly `Conforma CLI` for product-name references.

## Fix Focus Areas
- SECURITY.md[1-1]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 26, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:12 PM UTC · Completed 5:17 PM UTC

Commit: 87c4a29 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.37

@fullsend-ai-review

Copy link
Copy Markdown

Looks good to me

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Aug 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-for-merge All reviewers approved — ready to merge size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant