.github/SECURITY.md
Adam Moussa e9263123c7
docs: fix README review drift + add community-health files (#48)
INFRA-69: README documented the deleted claude-code-review.yaml workflow and
its rollout as the live PR-review setup. PR reviews are handled by the official
Claude Code App (since 2026-05-13); corrected the workflow list, added a PR
Reviews note, marked the legacy rollout script, and replaced the obsolete
rollout step. Preserved the claude-code-ci App + secrets (compliance-audit
still uses them).

INFRA-68: add SECURITY.md (private vuln reporting via GitHub advisory / email)
and SUPPORT.md (Jira INFRA, handbook, security pointer).
2026-06-10 15:35:31 -04:00

913 B

Security Policy

Sea-Haven-Industries repositories are private and for internal Sea Haven use.

Reporting a vulnerability

If you discover a security vulnerability in any Sea-Haven-Industries repository:

  • Do not open a public issue or describe the vulnerability in a pull request.
  • Open a private GitHub Security Advisory on the affected repository (Security → Advisories → Report a vulnerability), or
  • Email adam@seahavenind.com with the details.

Please include the affected repository and component, reproduction steps, and the potential impact. We aim to acknowledge reports within 2 business days.

Supported versions

These repositories back internal services that are deployed continuously from main. Only the currently deployed revision is supported — there are no tagged releases to patch retroactively. Fixes are rolled forward through the normal CI/CD pipeline.