Skip to content

docs: add SECURITY.md, CODEOWNERS, CONTRIBUTING.md; expand .gitignore#37

Merged
heznpc merged 1 commit into
mainfrom
docs/governance-and-gitignore
May 20, 2026
Merged

docs: add SECURITY.md, CODEOWNERS, CONTRIBUTING.md; expand .gitignore#37
heznpc merged 1 commit into
mainfrom
docs/governance-and-gitignore

Conversation

@heznpc

@heznpc heznpc commented May 20, 2026

Copy link
Copy Markdown
Member

Summary

Governance gaps from the 2026-05-21 modernization audit (P1 #9 + P2 #17, #18, #19 partial).

No code changes. No CI changes.

Test plan

  • No source files touched
  • CI green

Closes governance gaps identified in the 2026-05-21 modernization audit:

- SECURITY.md: private disclosure channels (GHSA + email), scope, response
  expectations, hardening posture self-attestation.
- CODEOWNERS: @heznpc default + explicit paths for publish workflows and audit
  primitives — wires up branch-protection 'require review from code owners' once enabled.
- CONTRIBUTING.md: quick-start, what merges fast vs. needs discussion, project
  conventions (heznpc sole author, no Co-Authored-By, EN/KO doc parity).
- .gitignore: add .env*/secrets, logs, OS/editor cruft, coverage, tsbuildinfo.
  push-protection is the last line of defense; .gitignore is the first.
@heznpc
heznpc merged commit f078e7b into main May 20, 2026
3 checks passed
@heznpc
heznpc deleted the docs/governance-and-gitignore branch May 20, 2026 23:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant