docs(governance): prepare public issue creation package
This commit is contained in:
@@ -0,0 +1,65 @@
|
||||
# Public issue template 006
|
||||
|
||||
## Title
|
||||
|
||||
[security] Prepare external security/code review checklist
|
||||
|
||||
## Labels
|
||||
|
||||
`security`, `review`, `governance`
|
||||
|
||||
## Purpose
|
||||
|
||||
Prepare a public checklist for future visible external security/code review.
|
||||
|
||||
## Background
|
||||
|
||||
Review checklist and CODEOWNERS exist, but active external peer review is not
|
||||
claimed until public reviewed pull requests or equivalent evidence exist.
|
||||
|
||||
## Scope
|
||||
|
||||
- Extend review evidence expectations from `docs/REVIEW_CHECKLIST_RU.md`.
|
||||
- Define security review scope and artifacts.
|
||||
- Define how reviewed PRs will be referenced.
|
||||
- Define forbidden data for public review comments.
|
||||
|
||||
## Non-goals
|
||||
|
||||
- No claim that external review is already active.
|
||||
- No publication of sensitive findings before triage.
|
||||
- Forbidden claim: automatic remediation is not claimed.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- External/security review checklist is documented.
|
||||
- Evidence format for reviewed PRs is defined.
|
||||
- Sensitive disclosure handling is documented.
|
||||
- First review remains pending until public evidence exists.
|
||||
|
||||
## Evidence required
|
||||
|
||||
- Checklist document.
|
||||
- Link to review policy.
|
||||
- Future reviewed PR URL or placeholder status.
|
||||
- Security disclosure guardrails.
|
||||
|
||||
## Safety/privacy guardrails
|
||||
|
||||
- Do not publish exploit details before coordinated handling.
|
||||
- Do not publish customer data, employee data or secrets.
|
||||
- Keep vulnerability handling aligned with `SECURITY.md`.
|
||||
|
||||
## Registry-positioning guardrails
|
||||
|
||||
- Do not claim active external peer review until public reviewed PRs exist.
|
||||
- Security review evidence is governance evidence, not certification.
|
||||
- Do not claim FSTEC/FSB certification.
|
||||
|
||||
## Checklist
|
||||
|
||||
- [ ] Draft external review checklist.
|
||||
- [ ] Define evidence requirements.
|
||||
- [ ] Define sensitive disclosure rules.
|
||||
- [ ] Link to `docs/REVIEW_CHECKLIST_RU.md`.
|
||||
- [ ] Record first reviewed PR only after it exists.
|
||||
Reference in New Issue
Block a user