Skip to content

[Docs] SECURITY_IMPLEMENTATION_SUMMARY.md and SECURITY.md overlap with no cross-reference, risking drift #1092

Description

@grantfox-oss

Join our community: https://t.me/+DOylgFv1jyJlNzM0

Why this matters

The repo root has both SECURITY.md (the standard GitHub-recognized policy) and SECURITY_IMPLEMENTATION_SUMMARY.md (an implementation-detail summary), plus .github/SECURITY_SETUP_CHECKLIST.md. None of the three link to each other, so a reader landing on one may not know the others exist, and updates to security posture risk being made in only one file.

Acceptance criteria

  • Add explicit cross-links between SECURITY.md, SECURITY_IMPLEMENTATION_SUMMARY.md, and .github/SECURITY_SETUP_CHECKLIST.md
  • Clarify each file's distinct purpose in its opening paragraph so contributors know which to read

Files to touch

  • SECURITY.md
  • SECURITY_IMPLEMENTATION_SUMMARY.md
  • .github/SECURITY_SETUP_CHECKLIST.md

Out of scope

  • Merging the three files into one
  • Changing the actual security controls described

Metadata

Metadata

Labels

GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Stellar WaveIssues in the Stellar wave programdocsDocumentationsecuritySecurity related tasks

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions