Skip to content

feat(KONFLUX-15176): add SECURITY.md for CRA - #549

Open
nmars wants to merge 1 commit into
conforma:mainfrom
nmars:add-security-md-for-cra
Open

feat(KONFLUX-15176): add SECURITY.md for CRA#549
nmars wants to merge 1 commit into
conforma:mainfrom
nmars:add-security-md-for-cra

Conversation

@nmars

@nmars nmars commented Aug 26, 2026

Copy link
Copy Markdown

Summary

  • Add SECURITY.md to comply with CRA (EU Cyber Resilience Act) requirements.

Jira: KONFLUX-15176

Signed-off-by: Nate Marsella <nmarsell@redhat.com>
@coderabbitai

coderabbitai Bot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8466fc28-c200-4fd5-ad79-f68fe04f2b4d


Comment @coderabbitai help to get the list of available commands.

@qodo-for-conforma

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can start a comment with 'qodo' or '@qodo' to chat about any finding

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@qodo-for-conforma

Copy link
Copy Markdown

PR Summary by Qodo

Add CRA security reporting guidance

📝 Documentation 🕐 Less than 5 minutes

Grey Divider

AI Description

• Adds repository-level security vulnerability and incident reporting guidance.
• Directs reporters to Conforma’s centralized policy for CRA compliance.
High-Level Assessment

A short repository-level SECURITY.md linking to the organization’s canonical policy is the appropriate approach because it avoids duplicating security procedures that could diverge over time.

Files changed (1) +5 / -0

Documentation (1) +5 / -0
SECURITY.mdAdd centralized security reporting instructions +5/-0

Add centralized security reporting instructions

• Adds repository-level instructions for reporting Conforma security vulnerabilities or incidents. The document links to the organization’s canonical security policy to support CRA compliance.

SECURITY.md

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 26, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:41 PM UTC · Completed 5:56 PM UTC

Commit: 87c4a29 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $3.67

@fullsend-ai-review

Copy link
Copy Markdown

Looks good to me

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Aug 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-for-merge All reviewers approved — ready to merge size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant