docs: add security policy
Metadata
Current evaluation
Merged a security policy document for Rockcraft, modeled after Snapcraft, covering the current 1.x release. Reviewers approved the changes, which were incorporated and merged successfully.
Suggested action: —
No scores available.
Issue body
For now it is very close to Snapcraft's, even though Rockcraft itself only has a single major release (1.x). As this documents the current policy, it does not make any references to interim bases - we'll need to update this document when we "oficially" support those.
- [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
---
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged a security policy document for Rockcraft, modeled after Snapcraft, covering the current 1.x release. Reviewers approved the changes, which were incorporated and merged successfully. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged documentation adding a security policy modeled after Snapcraft's, tailored for the current 1.x release. Reviewer suggestions were applied manually prior to merge. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged documentation adding a security policy modeled after Snapcraft's. Reviewer feedback was incorporated, establishing the current 1.x release guidelines with plans to update for interim bases. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #116 docs: add a security policy | imagecraft | merged | Merged documentation adding a security policy adapted from Rockcraft. The release cycle section was omitted pending the first stable release. Approved by two reviewers and passed CI checks. | |
| #274 docs: add security policy | craft-store | merged | Merged. Added a security policy document per CRAFT-4302. Approved by two reviewers, modified one file with 34 additions. | |
| #80 docs: add security policy | craft-grammar | merged | Merged addition of a security policy document. Approved by two reviewers, resolves CRAFT-4300, and adds 34 lines to a single file. | |
| #1037 docs: add security policy | craft-parts | merged | Merged security policy document addition. Approved by two reviewers with no unresolved comments, the change introduces 34 lines to one file and references CRAFT-4279. A changelog entry was omitted. | |
| #329 docs: add security policy | craft-cli | merged | Merged to add a security policy document, resolving CRAFT-4301. Approved by two reviewers with passing CI checks. The change modifies one file, adding 34 lines. | |
| #154 docs: add security policy | craft-archives | merged | Added security policy documentation. Merged after approval by two reviewers with zero unresolved comments. The change introduces 34 lines to one file and resolves CRAFT-4299. | |
| #2237 docs: add security policy | charmcraft | merged | Merged documentation update adding a security policy. The policy distinguishes Charmcraft from generated charms, outlines build isolation technologies, and clarifies base support alignment with Ubuntu. Approved by two reviewers. | |
| #1093 feat(snap): add rockcraft.json to the snap | rockcraft | merged | Merged a pull request adding rockcraft.json to the snap. Requested by the Rocks team, this enables users to validate rockcraft.yaml against their installed version and check supported bases. Approved by two reviewers and passed CI checks. | |
| #372 docs: add security policy | fetch-service | merged | Merged after two reviewer approvals, adding a security policy document. The change introduces 32 lines to a single file to establish project security reporting guidelines. | |
| #1056 docs: clean up 'rockcraft.yaml' | rockcraft | merged | Merged documentation cleanup for rockcraft.yaml. Updates include upgrading pydantic-kitbash to v0.1.1, removing unnecessary module declarations, and normalizing field order. Approved by two reviewers and merged despite unrelated snap-test failures. |