.github/SECURITY.md
Adam Moussa e9263123c7
docs: fix README review drift + add community-health files (#48)
INFRA-69: README documented the deleted claude-code-review.yaml workflow and
its rollout as the live PR-review setup. PR reviews are handled by the official
Claude Code App (since 2026-05-13); corrected the workflow list, added a PR
Reviews note, marked the legacy rollout script, and replaced the obsolete
rollout step. Preserved the claude-code-ci App + secrets (compliance-audit
still uses them).

INFRA-68: add SECURITY.md (private vuln reporting via GitHub advisory / email)
and SUPPORT.md (Jira INFRA, handbook, security pointer).
2026-06-10 15:35:31 -04:00

17 lines
913 B
Markdown

# Security Policy
Sea-Haven-Industries repositories are private and for internal Sea Haven use.
## Reporting a vulnerability
If you discover a security vulnerability in any Sea-Haven-Industries repository:
- **Do not** open a public issue or describe the vulnerability in a pull request.
- Open a private **GitHub Security Advisory** on the affected repository (**Security → Advisories → Report a vulnerability**), **or**
- Email **adam@seahavenind.com** with the details.
Please include the affected repository and component, reproduction steps, and the potential impact. We aim to acknowledge reports within 2 business days.
## Supported versions
These repositories back internal services that are deployed continuously from `main`. Only the currently deployed revision is supported — there are no tagged releases to patch retroactively. Fixes are rolled forward through the normal CI/CD pipeline.