Verified gap
No CONTRIBUTING.md or SECURITY.md at root, .github, or docs. Current GitHub policy page has no policy. Read-only GET /repos/2233admin/code-intel-pipeline/private-vulnerability-reporting on 2026-09-22 returns enabled=false. Matching issue search found no open concrete repair (only broad backlog #103 and closed audit #34). Open fix queue contains only unrelated #392.
Bounded repair approved for this session
Actual branch main; newcomer-docs owns new concise CONTRIBUTING.md and SECURITY.md plus README resource links. Contributor instructions use pinned Rust 1.95.0, cargo build --locked -p code-intel --bin code-intel, native --version/gates, focused tests actually exercised, installation regressions in install-smoke, no -D warnings/bulk dead-code cleanup. English/Chinese reports accepted. Contributors without label permission comment with intended branch/approach and request a maintainer apply claimed/coordinate before overlapping work.
Security policy states the actual limitation: private reporting is not enabled, no confidential channel is currently documented; never post exploits/secrets publicly. A non-sensitive public issue may request private coordination only, not serve as confidential disclosure. Do not invent email, SLA, support promises or a working Report vulnerability link. Do not change settings.
Separate unresolved maintainer action
Enable/provide and verify a genuine private vulnerability-reporting route, then update the policy. Documentation repair does not resolve the missing private channel.
Claim permission limitation
Current authenticated contributor Fancy0uth can create/comment but cannot AddLabelsToLabelable. Requested ownership: branch main, newcomer-docs bounded leaves above; maintainer must apply claimed. This is not a claim that the label exists.
Verified gap
No CONTRIBUTING.md or SECURITY.md at root, .github, or docs. Current GitHub policy page has no policy. Read-only GET /repos/2233admin/code-intel-pipeline/private-vulnerability-reporting on 2026-09-22 returns enabled=false. Matching issue search found no open concrete repair (only broad backlog #103 and closed audit #34). Open fix queue contains only unrelated #392.
Bounded repair approved for this session
Actual branch main; newcomer-docs owns new concise CONTRIBUTING.md and SECURITY.md plus README resource links. Contributor instructions use pinned Rust 1.95.0, cargo build --locked -p code-intel --bin code-intel, native --version/gates, focused tests actually exercised, installation regressions in install-smoke, no -D warnings/bulk dead-code cleanup. English/Chinese reports accepted. Contributors without label permission comment with intended branch/approach and request a maintainer apply claimed/coordinate before overlapping work.
Security policy states the actual limitation: private reporting is not enabled, no confidential channel is currently documented; never post exploits/secrets publicly. A non-sensitive public issue may request private coordination only, not serve as confidential disclosure. Do not invent email, SLA, support promises or a working Report vulnerability link. Do not change settings.
Separate unresolved maintainer action
Enable/provide and verify a genuine private vulnerability-reporting route, then update the policy. Documentation repair does not resolve the missing private channel.
Claim permission limitation
Current authenticated contributor Fancy0uth can create/comment but cannot AddLabelsToLabelable. Requested ownership: branch main, newcomer-docs bounded leaves above; maintainer must apply claimed. This is not a claim that the label exists.