Skip to content

docs: publish contributor steps and honest vulnerability coordination policy #398

Description

@Fancy0uth

Verified gap

No CONTRIBUTING.md or SECURITY.md at root, .github, or docs. Current GitHub policy page has no policy. Read-only GET /repos/2233admin/code-intel-pipeline/private-vulnerability-reporting on 2026-09-22 returns enabled=false. Matching issue search found no open concrete repair (only broad backlog #103 and closed audit #34). Open fix queue contains only unrelated #392.

Bounded repair approved for this session

Actual branch main; newcomer-docs owns new concise CONTRIBUTING.md and SECURITY.md plus README resource links. Contributor instructions use pinned Rust 1.95.0, cargo build --locked -p code-intel --bin code-intel, native --version/gates, focused tests actually exercised, installation regressions in install-smoke, no -D warnings/bulk dead-code cleanup. English/Chinese reports accepted. Contributors without label permission comment with intended branch/approach and request a maintainer apply claimed/coordinate before overlapping work.

Security policy states the actual limitation: private reporting is not enabled, no confidential channel is currently documented; never post exploits/secrets publicly. A non-sensitive public issue may request private coordination only, not serve as confidential disclosure. Do not invent email, SLA, support promises or a working Report vulnerability link. Do not change settings.

Separate unresolved maintainer action

Enable/provide and verify a genuine private vulnerability-reporting route, then update the policy. Documentation repair does not resolve the missing private channel.

Claim permission limitation

Current authenticated contributor Fancy0uth can create/comment but cannot AddLabelsToLabelable. Requested ownership: branch main, newcomer-docs bounded leaves above; maintainer must apply claimed. This is not a claim that the label exists.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    claimedIssue claimed by an active session (DR-0004): read the claim comment before touching it

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions