SECURITY.md: replace the no-releases-yet note with a supported-versions table

Open
#95 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
65/100
Issue type
Documentation
Clarity
Mostly clear
Activity status
Active
Tech stack
github

Research direction

Start in SECURITY.md and read the scoped-token discussion in README. Decide and document the supported release window, replace the no-releases-yet paragraph with a version/support table, align the advisory guidance with that policy, and verify the Atlassian token-revocation note against the current UI.

Written by the indexing model from the issue text.

Description

documentation

SECURITY.md currently says there is nothing to support yet:

markfluence has not had a release yet. Fixes land on main, which is the only supported version until 1.0.0. This section will get a version table when there is something to put in it.

That is accurate today and becomes wrong the moment 1.0.0 is tagged, which is exactly when nobody is looking at the security policy. Tagging is the trigger for this one.

Replace the paragraph with the table GitHub's conventional policy uses — a version (or version range) column and a supported yes/no column. The thing to actually decide, rather than the table markup, is the support window: whether only the latest release gets fixes, or the current minor line does too. Given that this is a CLI with no plugin surface and no long-lived deployment to upgrade around, "latest release only" is probably right and is the cheapest promise to keep, but it should be a decision rather than a default that fell out of the template.

Two related things worth handling in the same change:

  • The reporting section says disclosure is coordinated through a GitHub Security Advisory. Once there are releases, an advisory wants a fixed-in version, so the table and the advisory should agree about what a supported version means.
  • The token-revocation note asserts that an Atlassian API token cannot be rotated in place and recovery means issuing a new one. That matches the scoped-token discussion in the README but was never verified against Atlassian's current UI. Worth confirming while editing the file.

Added in #94.

Dominant language
Go
Stars
2
Forks
0
Avg merge
2h 5m
Merged PRs (30d)
50

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from mozilla/markfluence

All issues in mozilla/markfluence

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.