-
Notifications
You must be signed in to change notification settings - Fork 3.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
docs: Update More Info
link of SECURITY.md
#22042
Conversation
📝 WalkthroughWalkthroughThe changes in the Changes
Possibly related PRs
Suggested labels
Suggested reviewers
Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media? 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
Documentation and Community
|
More Info
linkMore Info
link of SECURITY.md
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 0
🧹 Outside diff range and nitpick comments (1)
SECURITY.md (1)
Line range hint
22-34
: Clear distinction between reporting methodsThe updated table clearly distinguishes between bounty-eligible and non-eligible reporting methods. This is a valuable clarification for potential reporters.
Consider adding a brief explanation of why email reports are not bounty-eligible to provide more context to the readers.
📜 Review details
Configuration used: .coderabbit.yml
Review profile: CHILL
📒 Files selected for processing (1)
- SECURITY.md (1 hunks)
🧰 Additional context used
📓 Path-based instructions (1)
SECURITY.md (1)
Pattern
**/*.md
: "Assess the documentation for misspellings, grammatical errors, missing documentation and correctness"
🔇 Additional comments (4)
SECURITY.md (4)
Line range hint
1-9
: Excellent addition of the security warningThe new warning effectively emphasizes the importance of not disclosing security vulnerabilities publicly. This addition enhances the document's clarity and aligns well with best practices for responsible disclosure.
Line range hint
11-20
: Clear definition of supported versionsThe scope section now clearly defines that security updates are supported for the latest release tag and the main branch. This clarification is valuable for users and contributors.
Line range hint
36-58
: Comprehensive guidelines for researchersThe expanded guidelines provide clear and specific instructions for researchers. The emphasis on confidentiality and avoiding disruption to production systems is particularly valuable. These additions will help ensure responsible vulnerability reporting.
60-64
: Updated link to examplesThe link to EXAMPLES.md has been correctly updated to reflect the new repository location. The new link points to a more specific resource (Classification Matrix with real-world examples), which should provide valuable context for users.
To ensure the new link is correct and accessible, please run the following command:
This command will check if the new URL is accessible. If it returns a status code of 200, the link is valid.
✅ Verification successful
Link Update Verified
The updated link to EXAMPLES.md is accessible and returns a status code of 200.
🏁 Scripts executed
The following scripts were executed for the analysis:
Script:
#!/bin/bash # Verify the accessibility of the new link curl -I https://github.com/interchainio/security/blob/main/resources/CLASSIFICATION_MATRIX.mdLength of output: 4967
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good
Description
Since cosmos/security has moved to interchainio/security, some links are not valid now.
The link to
Example
could be found in the new repo, others couldn't, so I deleted them...Summary by CodeRabbit
[email protected]
are not eligible for bounty rewards.EXAMPLES.md
to a new resource related to real-world examples.