docs: add a security policy
Metadata
Current evaluation
Merged documentation adding a security policy adapted from Rockcraft. The release cycle section was omitted pending the first stable release. Approved by two reviewers and passed CI checks.
Suggested action: —
No scores available.
Issue body
- [ ] Have you followed the guidelines for contributing?
- [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [ ] Have you successfully run `make lint && make test`?
---
This is slightly adapted from Rockcraft's security policy. The section about release cycle was omitted on purpose and should be added once a first stable version of Imagecraft is released.
CRAFT-4277
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged documentation adding a security policy adapted from Rockcraft. The release cycle section was omitted pending the first stable release. Approved by two reviewers and passed CI checks. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged documentation adding a security policy adapted from Rockcraft. The release cycle section was deferred until a stable release. Resolves CRAFT-4277. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged a security policy document adapted from Rockcraft. The release cycle section was deferred until the first stable release. Resolves CRAFT-4277. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #837 docs: add security policy | rockcraft | merged | Merged a security policy document for Rockcraft, modeled after Snapcraft, covering the current 1.x release. Reviewers approved the changes, which were incorporated and merged successfully. | |
| #274 docs: add security policy | craft-store | merged | Merged. Added a security policy document per CRAFT-4302. Approved by two reviewers, modified one file with 34 additions. | |
| #1037 docs: add security policy | craft-parts | merged | Merged security policy document addition. Approved by two reviewers with no unresolved comments, the change introduces 34 lines to one file and references CRAFT-4279. A changelog entry was omitted. | |
| #329 docs: add security policy | craft-cli | merged | Merged to add a security policy document, resolving CRAFT-4301. Approved by two reviewers with passing CI checks. The change modifies one file, adding 34 lines. | |
| #80 docs: add security policy | craft-grammar | merged | Merged addition of a security policy document. Approved by two reviewers, resolves CRAFT-4300, and adds 34 lines to a single file. | |
| #154 docs: add security policy | craft-archives | merged | Added security policy documentation. Merged after approval by two reviewers with zero unresolved comments. The change introduces 34 lines to one file and resolves CRAFT-4299. | |
| #2237 docs: add security policy | charmcraft | merged | Merged documentation update adding a security policy. The policy distinguishes Charmcraft from generated charms, outlines build isolation technologies, and clarifies base support alignment with Ubuntu. Approved by two reviewers. | |
| #372 docs: add security policy | fetch-service | merged | Merged after two reviewer approvals, adding a security policy document. The change introduces 32 lines to a single file to establish project security reporting guidelines. | |
| #671 docs: add security policy | craft-application | merged | Merged after approval by two reviewers and passing CI checks. Adds a security policy from Starbase. Maintainers requested enabling the GitHub advisories tab, pending security team feedback. | |
| #5324 docs: add security policy | snapcraft | merged | Merged documentation adding a security policy. Approved by two reviewers, the change adds 33 lines across two files and clarifies the relationship between bases and Ubuntu releases. |