docs: use the org-wide security policy - #282
Conversation
Remove the repository SECURITY.md; GitHub serves putdotio/.github SECURITY.md for every repo without its own.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
It is a safe docs-only deletion with no remaining references, and the equivalent org-wide security policy is confirmed to exist.
Review effort: Balanced
Findings: None
What changed in this PR
This PR removes the repository-local SECURITY.md so the repository falls back to the organization-wide put.io security policy that GitHub automatically surfaces for any repository lacking its own SECURITY.md. It is a documentation-only change that consolidates security reporting guidance to a single org-level source.
I verified the two claims in the description: a repository-wide search found no remaining references or links to SECURITY.md, and the org-wide putdotio/.github/SECURITY.md exists and covers the same contact (devs@put.io), testing-against-owned-accounts rule, and private-reporting guidance that the deleted file provided.
Changes:
- Deleted the repository's
SECURITY.md, deferring to the org-wide security policy.
| File | Description |
|---|---|
| SECURITY.md | Removed the repo-local security policy; coverage now comes from the org-wide putdotio/.github/SECURITY.md. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Change
The repo now uses the org-wide put.io security policy, which GitHub shows for every repository without its own
SECURITY.md.SECURITY.md; its contact, scope, and testing rules are covered by the org policyValidation
./gradlew verify: BUILD SUCCESSFUL (Java 21, Kotlin SDK at its default branch, 40736da)Written by an agent (Claude Code, Opus 5.5)