Skip to content

docs: define repository security policy - #136

Merged
zcrab-oai merged 1 commit into
mainfrom
codex/security-policy-20260827
Aug 27, 2026
Merged

docs: define repository security policy#136
zcrab-oai merged 1 commit into
mainfrom
codex/security-policy-20260827

Conversation

@zcrab-oai

Copy link
Copy Markdown
Contributor

Summary

  • Add a repository-wide security policy for the workspace manager and production plugins.
  • Document untrusted repository data, collaboration tunnels, Slack integrations, AI-agent boundaries, and sensitive tax documents.
  • Define reportable security impact, required filesystem and credential protections, and private vulnerability reporting.

Validation

  • git diff --cached --check
  • Resolved SECURITY.md for plugins/draw/src/server/http.ts with the Codex 安全 policy resolver.
  • Confirmed GitHub private vulnerability reporting is enabled.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 27, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-08-27T22:08:21.011030Z 53b399f PR opened
🔒 安全 Review Completed 2026-08-27T22:08:37.156810Z 53b399f PR opened
ℹ️ 关于 Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@zcrab-oai
zcrab-oai enabled auto-merge (squash) August 27, 2026 22:07
@zcrab-oai
zcrab-oai merged commit 3f1375f into main Aug 27, 2026
7 checks passed
@zcrab-oai
zcrab-oai deleted the codex/security-policy-20260827 branch August 27, 2026 22:08
注册 for free to join this conversation on GitHub. Already have an account? 登录 to comment

标签

None yet

项目

None yet

Development

Successfully merging this pull request may close these issues.

1 participant