mirror of
https://github.com/Sea-Haven-Industries/.github-private.git
synced 2026-09-30 06:53:14 +00:00
chore(ci): document CodeQL exclusion for .github-private (INFRA-49) (#4)
This commit is contained in:
parent
e6b05e1c6a
commit
a070b36197
1 changed files with 18 additions and 0 deletions
18
SECURITY.md
Normal file
18
SECURITY.md
Normal file
|
|
@ -0,0 +1,18 @@
|
||||||
|
# Security
|
||||||
|
|
||||||
|
## CodeQL Analysis
|
||||||
|
|
||||||
|
CodeQL code scanning is intentionally not configured for this repository.
|
||||||
|
|
||||||
|
This repo contains only the Sea Haven Industries organization profile
|
||||||
|
(`profile/README.md`) rendered to org members. It holds no CodeQL-analyzable
|
||||||
|
application code in any supported language (no JavaScript/TypeScript, Python,
|
||||||
|
Go, Java, C/C++, C#, Ruby, or Swift), so CodeQL would have nothing to scan.
|
||||||
|
|
||||||
|
This exclusion is deliberate and tracked under INFRA-49. If analyzable
|
||||||
|
application code is ever added here, wire in the org reusable CodeQL workflow
|
||||||
|
(as used by the application repos) at that time.
|
||||||
|
|
||||||
|
## Reporting
|
||||||
|
|
||||||
|
For security concerns, contact Adam Moussa (adam@seahavenind.com).
|
||||||
Loading…
Add table
Reference in a new issue