docs(security): org-wide SECURITY.md — responsible disclosure to security@moleculesai.app, 48h ack, 90d coordinated #3
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "docs/security-md-2026-05-06"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
First org-wide
SECURITY.md. GitHub renders<org>/.github/SECURITY.mdas the default security policy for any repo in the org that doesn't ship its own; mirroring the path on Gitea so once GitHub access is restored and repo-sync activates, it lands in the right place automatically.In-scope
security@moleculesai.app. Reviewer note (load-bearing): this address is a placeholder — please confirm the live mailbox / forwarding rule is in place before merging. The body of the file flags this in plain text too.git.moleculesai.app/molecule-ai/internal(parallel toCONTRIBUTING.mdPR-A).NOT-claimed (explicit)
Matches the orchestrator spec ("don't claim features we don't have").
Length
53 lines. Target was ~40; 13 lines over because the explicit reviewer-note + scope-out enumeration + the no-bounty/no-safe-harbour callouts add real signal. Trim if you want — flag the lines.
Independent of
PR-A (
CONTRIBUTING.md#2) — separate branch, not stacked.🤖 Generated with Claude Code
Hongming-confirmed (chat 2026-05-07): security@moleculesai.app Google Workspace group created + tested + members Hongming+Cui receiving inbound. Reviewer-note placeholder is now real. Merge.