Skip to content

Security: nsalvacao/Governance_as_Code

Security

SECURITY.md

title Security Policy
artifact_type policy
status public
visibility public
classification public
owner repository-maintainer
review_cadence semi-annual
applies_to this repository
source_basis GitHub Docs
source_manifests
governance__github_docs.md
alignment_mode direct-adaptation
updated 2026-03-27

Security Policy

Do not report unpatched or sensitive vulnerabilities through public issues.

Reporting

  1. Report vulnerabilities privately through GitHub Security Advisories before any public disclosure.
  2. Use a public issue only for already-public follow-up, non-sensitive remediation tracking, or governance changes that are safe to discuss openly.
  3. Include enough technical detail for triage, but avoid publishing secrets, exploit steps, or undisclosed weaknesses.

Scope

This policy covers the repository instance, its GitHub-native automation surfaces, and the reusable artifacts published here.

Source Attribution

  • Source manifests: governance__github_docs.md
  • Primary source basis: GitHub Docs
  • Alignment mode: direct-adaptation
  • Reviewed on: 2026-03-27

There aren't any published security advisories