From a070b361971220fcb030f2e85d0777104cf41f5f Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 6 Jul 2026 18:26:47 -0400 Subject: [PATCH] chore(ci): document CodeQL exclusion for .github-private (INFRA-49) (#4) --- SECURITY.md | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..e1c74bd --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,18 @@ +# Security + +## CodeQL Analysis + +CodeQL code scanning is intentionally not configured for this repository. + +This repo contains only the Sea Haven Industries organization profile +(`profile/README.md`) rendered to org members. It holds no CodeQL-analyzable +application code in any supported language (no JavaScript/TypeScript, Python, +Go, Java, C/C++, C#, Ruby, or Swift), so CodeQL would have nothing to scan. + +This exclusion is deliberate and tracked under INFRA-49. If analyzable +application code is ever added here, wire in the org reusable CodeQL workflow +(as used by the application repos) at that time. + +## Reporting + +For security concerns, contact Adam Moussa (adam@seahavenind.com).