docs: add top-level security entry point

This commit is contained in:
2026-08-30 23:17:57 +02:00
parent 060171d714
commit b486285027
+9
View File
@@ -0,0 +1,9 @@
# Security Policy
ForgeFlow's detailed security model is documented in [`docs/SECURITY.md`](docs/SECURITY.md).
Report suspected vulnerabilities privately to the repository owner. Do not publish Gitea tokens, SSH credentials, update-signing material, private server addresses, support bundles containing sensitive data or other operational secrets in a public issue.
For a useful report, include the affected ForgeFlow version/commit, component, minimal reproduction steps, expected and observed behaviour and security impact. Use sanitized or synthetic repository/server data whenever possible.
The current release model requires exact-commit verification, origin-constrained credential use, signed update manifests, redacted diagnostics and bounded deployment adapters. Changes must not silently weaken those guarantees.