mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 10:33:12 +00:00
INFRA-69: README documented the deleted claude-code-review.yaml workflow and its rollout as the live PR-review setup. PR reviews are handled by the official Claude Code App (since 2026-05-13); corrected the workflow list, added a PR Reviews note, marked the legacy rollout script, and replaced the obsolete rollout step. Preserved the claude-code-ci App + secrets (compliance-audit still uses them). INFRA-68: add SECURITY.md (private vuln reporting via GitHub advisory / email) and SUPPORT.md (Jira INFRA, handbook, security pointer).
17 lines
913 B
Markdown
17 lines
913 B
Markdown
# Security Policy
|
|
|
|
Sea-Haven-Industries repositories are private and for internal Sea Haven use.
|
|
|
|
## Reporting a vulnerability
|
|
|
|
If you discover a security vulnerability in any Sea-Haven-Industries repository:
|
|
|
|
- **Do not** open a public issue or describe the vulnerability in a pull request.
|
|
- Open a private **GitHub Security Advisory** on the affected repository (**Security → Advisories → Report a vulnerability**), **or**
|
|
- Email **adam@seahavenind.com** with the details.
|
|
|
|
Please include the affected repository and component, reproduction steps, and the potential impact. We aim to acknowledge reports within 2 business days.
|
|
|
|
## Supported versions
|
|
|
|
These repositories back internal services that are deployed continuously from `main`. Only the currently deployed revision is supported — there are no tagged releases to patch retroactively. Fixes are rolled forward through the normal CI/CD pipeline.
|