Skip to content

feat(KONFLUX-15176): add SECURITY.md for CRA - #28

Merged
robnester-rh merged 1 commit into
conforma:mainfrom
nmars:add-security-md-for-cra
Sep 9, 2026
Merged

robnester-rh merged 1 commit into
conforma:mainfrom
nmars:add-security-md-for-cra

Conversation

@nmars

@nmars nmars commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add SECURITY.md to comply with CRA (EU Cyber Resilience Act) requirements.

Jira: KONFLUX-15176

Signed-off-by: Nate Marsella <nmarsell@redhat.com>
@coderabbitai

coderabbitai Bot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 97c8cff3-fcb4-475a-98a1-42ec724c92bf


Comment @coderabbitai help to get the list of available commands.

@qodo-for-conforma

Copy link
Copy Markdown

PR Summary by Qodo

Add CRA-compliant security reporting guidance

📝 Documentation 🕐 Less than 5 minutes

Grey Divider

AI Description

• Add a repository security policy to support Cyber Resilience Act compliance.
• Direct vulnerability and incident reports to Conforma’s centralized security instructions.
High-Level Assessment

Linking to Conforma’s centralized security policy is the appropriate approach because it provides one maintained source of truth and avoids duplicating reporting instructions across repositories.

Files changed (1) +5 / -0

Documentation (1) +5 / -0
SECURITY.mdAdd centralized security reporting policy +5/-0

Add centralized security reporting policy

• Adds repository-level guidance for reporting Conforma security vulnerabilities or incidents. The document directs reporters to the organization’s centrally maintained security policy.

SECURITY.md

@qodo-for-conforma

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can start a comment with 'qodo' or '@qodo' to chat about any finding

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@codecov

codecov Bot commented Sep 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
unit-tests 0.96% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@robnester-rh
robnester-rh merged commit a1f0831 into conforma:main Sep 9, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants