From 732d9dad2cc750a32c350d5a7aa744ca1ac35e63 Mon Sep 17 00:00:00 2001 From: Altay Date: Fri, 2 Oct 2026 13:56:36 +0300 Subject: [PATCH] docs: use the org-wide security policy Drop the per-repo SECURITY.md in favor of putdotio/.github's policy and stop packaging it. --- README.md | 4 +++- SECURITY.md | 36 ------------------------------------ docs/DISTRIBUTION.md | 4 ++-- package.json | 1 - test/package-config.test.ts | 2 +- 5 files changed, 6 insertions(+), 41 deletions(-) delete mode 100644 SECURITY.md diff --git a/README.md b/README.md index 4c5c5f4..ab0a0a6 100644 --- a/README.md +++ b/README.md @@ -23,6 +23,8 @@ Requires the Node version in `engines.node` of [`package.json`](./package.json); pnpm add -D @putdotio/rokit ``` +Only the latest published version receives routine fixes. + ## Quick Start Set the target Roku in the app repo that consumes `rokit`: @@ -192,7 +194,7 @@ artifacts. - [Roku debugging](./docs/DEBUGGING.md) - [Distribution](./docs/DISTRIBUTION.md) - [rokit skill](./skills/rokit/SKILL.md) -- [Security](./SECURITY.md) +- [Security](https://github.com/putdotio/.github/blob/main/SECURITY.md) ## Repo Internals diff --git a/SECURITY.md b/SECURITY.md deleted file mode 100644 index c16c78b..0000000 --- a/SECURITY.md +++ /dev/null @@ -1,36 +0,0 @@ -# Security - -If you believe you have found a security or privacy issue in this project, -please report it privately. - -## Contact - -- email: devs@put.io - -If you are unsure whether something is sensitive, email first instead of opening -a public issue. - -## Scope - -Useful reports usually include issues involving: - -- token, secret, or credential exposure -- unsafe handling of device passwords or signing keys -- command injection through CLI arguments, env values, or device responses -- publishing, release, or package integrity problems -- private device, account, or media identifier exposure - -## Guidelines - -- test only against devices, accounts, environments, and data you control -- keep testing non-destructive, low-volume, and service-safe -- do not include device passwords, signing keys, account tokens, private content IDs, or local device identifiers in public issues, pull requests, examples, or logs - -## Supported Versions - -Only the latest published version receives routine fixes. - -## Disclosure - -Please allow a reasonable amount of time to investigate and fix the issue before -sharing details publicly. diff --git a/docs/DISTRIBUTION.md b/docs/DISTRIBUTION.md index 111cff4..550808b 100644 --- a/docs/DISTRIBUTION.md +++ b/docs/DISTRIBUTION.md @@ -32,8 +32,8 @@ Release writes use the `putio-releaser` installation token. The default `GITHUB_ `files` in [`package.json`](../package.json) lists what the npm package ships. It carries the docs, consumer skill, and -generic live probe so agents consuming the package can inspect distribution, -security, and Roku proof mechanics without cloning the repository. Packaged docs +generic live probe so agents consuming the package can inspect distribution +and Roku proof mechanics without cloning the repository. Packaged docs link files outside the tarball by absolute GitHub URL. The published dependencies pin Effect, platform-node, and platform-node-shared to diff --git a/package.json b/package.json index fa64a6b..4e25e7a 100644 --- a/package.json +++ b/package.json @@ -28,7 +28,6 @@ "docs", "examples", "README.md", - "SECURITY.md", "skills" ], "type": "module", diff --git a/test/package-config.test.ts b/test/package-config.test.ts index b0ad903..6e549e1 100644 --- a/test/package-config.test.ts +++ b/test/package-config.test.ts @@ -25,7 +25,7 @@ describe("package config", () => { const packageConfig = readPackageConfig(); expect(packageConfig.files).toEqual( - expect.arrayContaining(["AGENTS.md", "docs", "examples", "README.md", "SECURITY.md"]), + expect.arrayContaining(["AGENTS.md", "docs", "examples", "README.md"]), ); }); });