Add SECURITY.md to templates
Metadata
Current evaluation
Request to add SECURITY.md to templates. Work completed in starbase#356 (merged). Issue is stale with no activity since Nov 2024.
Suggested action: close stale
Reason: The requested work has been completed via starbase#356 (merged), which adds a SECURITY.md template to standardize vulnerability reporting. The issue has been inactive since November 2024, and the original blocker (starbase#82) is now closed with the implementation merged.
Impact:
40
Quick Win:
34.0
Staleness:
85
Complexity:
15
Confidence:
80
Support Request:
20
Issue body
### What needs to get done
We should probably add a [SECURITY.md](https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository) file to all templates.
Or link to a [company-wide](https://github.com/canonical/.github) SECURITY.md ([example](https://github.com/microsoft/.github/blob/main/SECURITY.md)).
Cross-posted: https://github.com/canonical/.github/issues/6
### Why it needs to get done
This is becoming standard practice.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen3.6-35b-a3b-mtp-q6 |
Impact:
40
Quick Win:
34.0
Staleness:
85
Complexity:
15
Confidence:
80
Support Request:
20
|
close stale | Request to add SECURITY.md to templates. Work completed in starbase#356 (merged). Issue is stale with no activity since Nov 2024. | |
| qwen/qwen3.8-27b |
Impact:
25
Quick Win:
17.5
Staleness:
65
Complexity:
30
Confidence:
72
Support Request:
10
|
keep open | Request to add SECURITY.md to charmcraft templates. Acknowledged by maintainer as team-wide effort via starbase. Starbase#356 merged the template, but charmcraft templates still lack it. Author questioned premise in Nov 2024; unresolved. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
85
Complexity:
10
Confidence:
85
Support Request:
10
|
close stale | Suggests adding a SECURITY.md file to project templates for standard security practices. Currently open but inactive for over a year, with a Jira ticket created and team-wide handling referenced elsewhere. | |
| qwen3.6-35b-a3b-mtp-q6 |
Staleness:
90
Complexity:
10
Confidence:
85
Support Request:
10
|
close stale | Request to add a SECURITY.md file to project templates, noted as being handled team-wide via another issue and questioned for relevance to this specific project. | |
| qwen3.6-35b-a3b-mtp-q6 |
Staleness:
85
Complexity:
10
Confidence:
85
Support Request:
10
|
close stale | Suggests adding a SECURITY.md file to templates or linking to a company-wide policy. Deferred to a team-wide starbase initiative and cross-posted elsewhere, with recent discussion questioning its relevance to this repo. | |
| qwen3.6-35b-a3b-mtp-q6 |
Staleness:
85
Complexity:
10
Confidence:
85
Support Request:
10
|
close stale | Proposes adding a SECURITY.md file or company-wide link to all templates to meet security standards. Currently deferred pending a team-wide starbase update. Internal ticket CRAFT-3709 created. Awaiting broader implementation. |
Update history
No update history recorded yet.
Related work
-
Likely Fixed By:
starbase#356
(confidence 90%)
starbase#356 was merged to add a SECURITY.md template, which addresses the core request of this issue.
-
Related To:
starbase#82
(confidence 85%)
Original issue tracking security policy implementation, now closed with starbase#356 merged.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #277 Add a SECURITY.md file | starbase | closed | Closed as a duplicate of canonical/starbase/issues/82. The request to add a SECURITY.md file was superseded by the referenced issue, which tracks the same requirement for vulnerability reporting. | |
| #356 docs: add SECURITY.md template | starbase | merged | Merged to add a SECURITY.md template. Approved by three reviewers and vetted by the Security Engineering team. References CRAFT-3700. Adds 46 lines across two files detailing security policies and vulnerability reporting. | |
| #671 docs: add security policy | craft-application | merged | Merged after approval by two reviewers and passing CI checks. Adds a security policy from Starbase. Maintainers requested enabling the GitHub advisories tab, pending security team feedback. | |
| #82 Security policy | starbase | closed | Resolved by merging pull request #356, which added the requested SECURITY.md file and repository security policy. |