docs(security): document Security Champion rotation and response team - #4223
Conversation
Surface into the public SECURITY.md the rotating Security Champion policy (6-month term, one-week handoff) and the security response team's composition and cross-organization diversity, previously defined only in the CVE-scanning pipeline's private governance document. Record @tym83 as the current champion, filling the role the GTR and this file flagged as unassigned. Signed-off-by: Timur Tukaev <[email protected]>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 8 included reviews per hour; 6 remain after this review. 📝 WalkthroughWalkthrough
ChangesSecurity documentation
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Merge Risk: ⚪ Minimal · up to This documentation update does not introduce an identified production or security risk. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
IvanHunters
left a comment
There was a problem hiding this comment.
Verdict
LGTM with non-blocking notes
Nine lines, and they say what the title says. The rotation cadence, the handoff overlap, the quarterly review and the roster all hold up against MAINTAINERS.md and against the rest of the file. The Trivy paragraph is updated in the same diff, so the document stays consistent with itself.
Findings
- [MINOR]
SECURITY.md:106, the response-team roster is now stated twice
Notes on merge order, not defects in this PR
Three documents disagree with this one until their own PRs land, and each is fixed elsewhere rather than here:
GENERAL_TECHNICAL_REVIEW.mdstill says the role is unassigned. #4221 rewrites those passages to name the holder.SECURITY.mdat this head still says publishing the pipeline policy documents is outstanding. #4224 publishes them.- The org-level
SECURITY.mdincozystack/.github, added by that repo's #8, carries the pre-change wording and has no sync mechanism.
None blocks this change. They do mean the set wants landing together, or in an order someone has chosen deliberately.
Checked and not a problem
The six monthly reports under docs/security/reports/ say the role is unassigned. They are dated snapshots, and the statement was true for the month each one covers. Rewriting them would edit a published record, so leaving them alone is correct.
|
|
||
| ### Security response team and rotation | ||
|
|
||
| Vulnerability reports are triaged by the maintainers responsible for security response — [@kvaps](https://github.com/kvaps), [@lexfrei](https://github.com/lexfrei), [@tym83](https://github.com/tym83), [@matthieu-robin](https://github.com/matthieu-robin) and [@mattia-eleuteri](https://github.com/mattia-eleuteri) — and any maintainer can receive a report and route it. The team spans more than one organization (Ænix, HIDORA) and more than one country, rather than sitting with a single employer. |
There was a problem hiding this comment.
[MINOR] the response-team roster is now stated twice
The same five names already appear at SECURITY.md:37, as reporting channel 2, in almost the same sentence:
Reports are triaged by the maintainers responsible for security response — Andrei Kvapil (@kvaps), Aleksei Sviridkin (@lexfrei), Timur Tukaev (@tym83), Matthieu ROBIN (@matthieu-robin) and mattia-eleuteri — but any maintainer can receive a report and route it.
Two copies mean a membership change has to be caught in both places, and missing one reintroduces exactly the drift this PR closes. Point one section at the other instead of restating the list.
…laim Addresses @IvanHunters round-2 review: - governance description at :20 now agrees with GOVERNANCE.md: the Directors removal (#4296) has merged, so three roles / one vote per Maintainer matches main. - drop the SECURITY.md rotation-publication item from the status banner and the :151 marker: #4223 merged and the rotation cadence + diversity statement are now in the published SECURITY.md; link to it instead. - re-verify the nightly-CI claim re-dated by the Date Updated bump: 1 of the last 24 scheduled runs passed (isolated passes 2026-08-17 and 2026-09-03), not six, and it has not 'failed every run since 2026-08-02'. - banner now says attribution-notice markers 'are to be resolved in place' (intent, not state), since :144-:145 still carry [maintainers: confirm]. Signed-off-by: Timur Tukaev <[email protected]>
What this PR does
Surfaces the Security Champion rotation policy and the security response team's composition and diversity into the public
SECURITY.md. Until now these were defined only in the CVE-scanning pipeline's private governance document, which the General Technical Review flagged as a gap (the policy existed but was unpublished, and the rotating role was unassigned).Specifically:
This is a policy change to a
CODEOWNERS-protected file and is intended for maintainer (CODEOWNER) review rather than a wording check.Downstream repositories
Release note
Summary by CodeRabbit