Skip to content

docs: point SECURITY.md at GitHub Security Advisories (v1.x) - #3602

Merged
maxisbey merged 1 commit into
v1.xfrom
docs/v1x-security-policy-ghsa
Sep 30, 2026
Merged

maxisbey merged 1 commit into
v1.xfrom
docs/v1x-security-policy-ghsa

Conversation

@claude

@claude claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Requested by Max Isbey · Slack thread

Before: SECURITY.md on v1.x says the SDK is maintained by Anthropic and directs vulnerability reports to the HackerOne anthropic-vdp program, which is no longer in use.

After: SECURITY.md on v1.x is identical to the one on main: it asks reporters to use this repository's GitHub Security Advisory (private vulnerability reporting), not to file public issues, and lists what to include in a report. It also now carries the Supported Versions table from main, which states which release lines receive fixes.

Backports the main security policy (#2092) to the v1.x maintenance branch so both supported lines carry the same reporting instructions. Docs-only change; no code or release impact.

Backport the security policy from main to v1.x. The HackerOne program
this file referenced is no longer in use; vulnerability reports for this
repository go through GitHub private vulnerability reporting.
@claude
claude Bot force-pushed the docs/v1x-security-policy-ghsa branch from ecfbf1a to 33cab58 Compare September 30, 2026 20:42

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nothing blocking. The comments below are optional suggestions. There is no need to push a fix for them before merging.

LGTM — docs-only rewrite of SECURITY.md; the inline notes are commit/PR-message hygiene nits, not problems with the file content.

Extended reasoning...

The diff touches only SECURITY.md, replacing the HackerOne reporting instructions with a Supported Versions table and a pointer to GitHub private vulnerability reporting; no code, config, or tests change and there is no CODEOWNERS file covering it. The only security-relevant aspect is where reporters are directed, and the new text matches the policy the PR says already lives on main. The two inline findings concern the Co-Authored-By and Claude-Session trailers in the commit and the tool mention in the PR body, which CLAUDE.md forbids, and are fixable by rewording the commit and description without altering the diff. Line length and table-drift candidates were examined and ruled out as non-issues for a Markdown file. The shallow clone has no branch refs, so the claim that the file is byte-identical to main was not independently verified here.

Additional findings (no inline location):

  • 🟡 SECURITY.md — nit: PR checklist — CLAUDE.md forbids co-authored-by lines and any mention of the tool used to create the commit or PR (rule stated under both the commit and Pull Requests sections). The PR description ends with "Generated with Claude Code" plus a session link and a "Generated by Claude Code" footer, and the commit ecfbf1a carries a Co-Authored-By: Claude ... trailer and a Claude-Session: line. Fix: strip the attribution/tool lines from the PR description and reword the commit (drop the Co-Authored-By and Claude-Session trailers) before merge.

    Why this was flagged

    Nothing fails at runtime; this is a docs-only change. The instruction guards the repository's commit/PR hygiene convention: the maintainers state twice that commit messages and PRs must never carry co-authored-by-style attribution or name the generating tool. As written, the commit message would land in v1.x history with both a Co-Authored-By trailer and a Claude-Session line, and the PR description names Claude Code twice with session links. The author needs to edit the PR description and amend/squash the commit message to remove those lines.

    Verification: Base CLAUDE.md (git show 8c2fa6e:CLAUDE.md) states twice, once in the commit-conventions bullets and once under "## Pull Requests": "NEVER ever mention a co-authored-by or similar aspects. In particular, never mention the tool used to create the commit message or PR."

Comment thread SECURITY.md
@maxisbey
maxisbey merged commit 2e16bc8 into v1.x Sep 30, 2026
29 checks passed
@maxisbey
maxisbey deleted the docs/v1x-security-policy-ghsa branch September 30, 2026 20:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants