Skip to content

docs(security): document Security Champion rotation and response team - #4223

Merged
Timur Tukaev (tym83) merged 1 commit into
mainfrom
security/champion-rotation-policy
Sep 17, 2026
Merged

Timur Tukaev (tym83) merged 1 commit into
mainfrom
security/champion-rotation-policy

Conversation

@tym83

@tym83 Timur Tukaev (tym83) commented Sep 12, 2026 •

Copy link
Copy Markdown
Collaborator

What this PR does

Surfaces the Security Champion rotation policy and the security response team's composition and diversity into the public SECURITY.md. Until now these were defined only in the CVE-scanning pipeline's private governance document, which the General Technical Review flagged as a gap (the policy existed but was unpublished, and the rotating role was unassigned).

Specifically:

  • Adds a "Security response team and rotation" subsection: names the response-team maintainers, notes the team spans more than one organization (Ænix, HIDORA) and more than one country, and documents the rotating Security Champion role — its responsibilities, a 6-month rotation among maintainers, and a one-week handoff overlap.
  • Records Timur Tukaev (@tym83) as the current Security Champion, filling the role this file previously described as unfilled.
  • Updates the Trivy paragraph accordingly (the triage-clock owner is no longer "currently unfilled").

This is a policy change to a CODEOWNERS-protected file and is intended for maintainer (CODEOWNER) review rather than a wording check.

Downstream repositories

  • No downstream repository is affected by this change

Release note

docs(security): document the Security Champion rotation policy and security response team in SECURITY.md

Summary by CodeRabbit

  • Documentation
    • Added information about the security response team and its rotating Security Champion role.
    • Clarified ownership of security triage timing and response coordination.

Surface into the public SECURITY.md the rotating Security Champion policy (6-month term, one-week handoff) and the security response team's composition and cross-organization diversity, previously defined only in the CVE-scanning pipeline's private governance document. Record @tym83 as the current champion, filling the role the GTR and this file flagged as unassigned.

Signed-off-by: Timur Tukaev <[email protected]>
@coderabbitai

coderabbitai Bot commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: ca43ed3e-f9c3-410b-8fd4-386193313d9e

📥 Commits

Reviewing files that changed from the base of the PR and between e3ab40e and 7f42f0a.

📒 Files selected for processing (1)
  • SECURITY.md

Included review availability: Your plan provides up to 8 included reviews per hour; 6 remain after this review.


📝 Walkthrough

Walkthrough

SECURITY.md documents the security response team, the six-month Security Champion rotation, quarterly reviews, and the current owner of CVE triage and remediation clocks.

Changes

Security documentation

Layer / File(s) Summary
Security response rotation and triage ownership
SECURITY.md
Adds the security response team and rotation process. Documents quarterly security reviews and updates the current Trivy triage owner.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 7f42f

This documentation update does not introduce an identified production or security risk.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main documentation changes: the Security Champion rotation and security response team.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch security/champion-rotation-policy

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added area/uncategorized PR auto-labeler could not map title scope to a known area/*; please review kind/documentation Categorizes issue or PR as related to documentation size/S This PR changes 10-29 lines, ignoring generated files labels Sep 12, 2026
@tym83
Timur Tukaev (tym83) marked this pull request as ready for review September 16, 2026 04:38

@IvanHunters IvanHunters left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

LGTM with non-blocking notes

Nine lines, and they say what the title says. The rotation cadence, the handoff overlap, the quarterly review and the roster all hold up against MAINTAINERS.md and against the rest of the file. The Trivy paragraph is updated in the same diff, so the document stays consistent with itself.

Findings

  • [MINOR] SECURITY.md:106, the response-team roster is now stated twice

Notes on merge order, not defects in this PR

Three documents disagree with this one until their own PRs land, and each is fixed elsewhere rather than here:

  • GENERAL_TECHNICAL_REVIEW.md still says the role is unassigned. #4221 rewrites those passages to name the holder.
  • SECURITY.md at this head still says publishing the pipeline policy documents is outstanding. #4224 publishes them.
  • The org-level SECURITY.md in cozystack/.github, added by that repo's #8, carries the pre-change wording and has no sync mechanism.

None blocks this change. They do mean the set wants landing together, or in an order someone has chosen deliberately.

Checked and not a problem

The six monthly reports under docs/security/reports/ say the role is unassigned. They are dated snapshots, and the statement was true for the month each one covers. Rewriting them would edit a published record, so leaving them alone is correct.

Comment thread SECURITY.md

### Security response team and rotation

Vulnerability reports are triaged by the maintainers responsible for security response — [@kvaps](https://github.com/kvaps), [@lexfrei](https://github.com/lexfrei), [@tym83](https://github.com/tym83), [@matthieu-robin](https://github.com/matthieu-robin) and [@mattia-eleuteri](https://github.com/mattia-eleuteri) — and any maintainer can receive a report and route it. The team spans more than one organization (Ænix, HIDORA) and more than one country, rather than sitting with a single employer.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[MINOR] the response-team roster is now stated twice

The same five names already appear at SECURITY.md:37, as reporting channel 2, in almost the same sentence:

Reports are triaged by the maintainers responsible for security response — Andrei Kvapil (@kvaps), Aleksei Sviridkin (@lexfrei), Timur Tukaev (@tym83), Matthieu ROBIN (@matthieu-robin) and mattia-eleuteri — but any maintainer can receive a report and route it.

Two copies mean a membership change has to be caught in both places, and missing one reintroduces exactly the drift this PR closes. Point one section at the other instead of restating the list.

@tym83
Timur Tukaev (tym83) merged commit 69c4fad into main Sep 17, 2026
20 checks passed
@tym83
Timur Tukaev (tym83) deleted the security/champion-rotation-policy branch September 17, 2026 03:08
Timur Tukaev (tym83) added a commit that referenced this pull request Sep 17, 2026
…laim

Addresses @IvanHunters round-2 review:
- governance description at :20 now agrees with GOVERNANCE.md: the Directors removal (#4296) has merged, so three roles / one vote per Maintainer matches main.
- drop the SECURITY.md rotation-publication item from the status banner and the :151 marker: #4223 merged and the rotation cadence + diversity statement are now in the published SECURITY.md; link to it instead.
- re-verify the nightly-CI claim re-dated by the Date Updated bump: 1 of the last 24 scheduled runs passed (isolated passes 2026-08-17 and 2026-09-03), not six, and it has not 'failed every run since 2026-08-02'.
- banner now says attribution-notice markers 'are to be resolved in place' (intent, not state), since :144-:145 still carry [maintainers: confirm].

Signed-off-by: Timur Tukaev <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/uncategorized PR auto-labeler could not map title scope to a known area/*; please review kind/documentation Categorizes issue or PR as related to documentation size/S This PR changes 10-29 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants