← Back to issue list

Add SECURITY.md to templates

View original Github issue

Metadata

Project
charmcraft
Number
#1125
Type
issue
State
open
Author
sed-i
Labels
Created
Updated
Closed

Current evaluation

Request to add SECURITY.md to templates. Work completed in starbase#356 (merged). Issue is stale with no activity since Nov 2024.

Suggested action: close stale

Reason: The requested work has been completed via starbase#356 (merged), which adds a SECURITY.md template to standardize vulnerability reporting. The issue has been inactive since November 2024, and the original blocker (starbase#82) is now closed with the implementation merged.

Impact: 40 Quick Win: 34.0 Staleness: 85 Complexity: 15 Confidence: 80 Support Request: 20

Issue body

### What needs to get done We should probably add a [SECURITY.md](https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository) file to all templates. Or link to a [company-wide](https://github.com/canonical/.github) SECURITY.md ([example](https://github.com/microsoft/.github/blob/main/SECURITY.md)). Cross-posted: https://github.com/canonical/.github/issues/6 ### Why it needs to get done This is becoming standard practice.

Evaluation history

Date Model Scores Action Summary
qwen3.6-35b-a3b-mtp-q6
Impact: 40
Quick Win: 34.0
Staleness: 85
Complexity: 15
Confidence: 80
Support Request: 20
close stale Request to add SECURITY.md to templates. Work completed in starbase#356 (merged). Issue is stale with no activity since Nov 2024.
qwen/qwen3.8-27b
Impact: 25
Quick Win: 17.5
Staleness: 65
Complexity: 30
Confidence: 72
Support Request: 10
keep open Request to add SECURITY.md to charmcraft templates. Acknowledged by maintainer as team-wide effort via starbase. Starbase#356 merged the template, but charmcraft templates still lack it. Author questioned premise in Nov 2024; unresolved.
qwen/qwen3.6-35b-a3b
Staleness: 85
Complexity: 10
Confidence: 85
Support Request: 10
close stale Suggests adding a SECURITY.md file to project templates for standard security practices. Currently open but inactive for over a year, with a Jira ticket created and team-wide handling referenced elsewhere.
qwen3.6-35b-a3b-mtp-q6
Staleness: 90
Complexity: 10
Confidence: 85
Support Request: 10
close stale Request to add a SECURITY.md file to project templates, noted as being handled team-wide via another issue and questioned for relevance to this specific project.
qwen3.6-35b-a3b-mtp-q6
Staleness: 85
Complexity: 10
Confidence: 85
Support Request: 10
close stale Suggests adding a SECURITY.md file to templates or linking to a company-wide policy. Deferred to a team-wide starbase initiative and cross-posted elsewhere, with recent discussion questioning its relevance to this repo.
qwen3.6-35b-a3b-mtp-q6
Staleness: 85
Complexity: 10
Confidence: 85
Support Request: 10
close stale Proposes adding a SECURITY.md file or company-wide link to all templates to meet security standards. Currently deferred pending a team-wide starbase update. Internal ticket CRAFT-3709 created. Awaiting broader implementation.

Update history

No update history recorded yet.

Related work

  • Likely Fixed By: starbase#356 (confidence 90%)

    starbase#356 was merged to add a SECURITY.md template, which addresses the core request of this issue.

  • Related To: starbase#82 (confidence 85%)

    Original issue tracking security policy implementation, now closed with starbase#356 merged.

Related issues

Issue Project State Summary Similarity
#277 Add a SECURITY.md file starbase closed Closed as a duplicate of canonical/starbase/issues/82. The request to add a SECURITY.md file was superseded by the referenced issue, which tracks the same requirement for vulnerability reporting.
82%
#356 docs: add SECURITY.md template starbase merged Merged to add a SECURITY.md template. Approved by three reviewers and vetted by the Security Engineering team. References CRAFT-3700. Adds 46 lines across two files detailing security policies and vulnerability reporting.
74%
#671 docs: add security policy craft-application merged Merged after approval by two reviewers and passing CI checks. Adds a security policy from Starbase. Maintainers requested enabling the GitHub advisories tab, pending security team feedback.
71%
#82 Security policy starbase closed Resolved by merging pull request #356, which added the requested SECURITY.md file and repository security policy.
71%