Problem Statement. SECURITY.md directs reporters to "the contact information in
the README." README.md has no security contact.
Technical Context.
SECURITY.md,
README.md,
.github/SECURITY-INSIGHTS.yml.
Expected Outcome.
SECURITY.md lists security@chainforge.app (or GitHub Security Advisories
fallback).
- A
.github/SECURITY-INSIGHTS.yml file declares supported versions, languages, and
security policy.
Acceptance Criteria.
- A test command
gh api repos/ChainForgee/ChainForge/security-advisories returns the
configured contact.
Files or modules likely to be affected.
SECURITY.md,
new .github/SECURITY-INSIGHTS.yml,
README.md.
Difficulty. Easy
Estimated effort. XS
Backlog item #98 from `docs/maintainer-issue-backlog.md.
Problem Statement.
SECURITY.mddirects reporters to "the contact information inthe README."
README.mdhas no security contact.Technical Context.
SECURITY.md,README.md,.github/SECURITY-INSIGHTS.yml.Expected Outcome.
SECURITY.mdlistssecurity@chainforge.app(or GitHub Security Advisoriesfallback).
.github/SECURITY-INSIGHTS.ymlfile declares supported versions, languages, andsecurity policy.
Acceptance Criteria.
gh api repos/ChainForgee/ChainForge/security-advisoriesreturns theconfigured contact.
Files or modules likely to be affected.
SECURITY.md,new
.github/SECURITY-INSIGHTS.yml,README.md.Difficulty. Easy
Estimated effort. XS
Backlog item #98 from `docs/maintainer-issue-backlog.md.