diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..742fc8b --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,3 @@ +# Every path has an owner, so GitHub requests a review from the founders team +# on each pull request. +* @scadable/founders diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..a246a7c --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,35 @@ +# Dependabot version updates. Weekly, at most five open pull requests per +# ecosystem, and minor and patch updates grouped into one pull request per +# ecosystem so they arrive together. A major update opens on its own, except +# for GitHub Actions, where every update is grouped (see that entry). +# Dependabot only opens pull requests; nothing in this file merges one. +version: 2 +updates: + - package-ecosystem: "uv" + directory: "/" + schedule: + interval: "weekly" + open-pull-requests-limit: 5 + commit-message: + prefix: "chore" + include: "scope" + groups: + uv-minor-and-patch: + patterns: + - "*" + update-types: + - "minor" + - "patch" + + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + open-pull-requests-limit: 5 + commit-message: + prefix: "chore" + include: "scope" + groups: + github-actions: + patterns: + - "*" diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..df829a3 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,23 @@ +# Security policy + +## Reporting a vulnerability + +Please do not report security problems through public issues, discussions or +pull requests. + +Email security@scadable.com with: + +- what you found, and where: the URL, endpoint or repository; +- the steps to reproduce it; +- the impact you think it has; +- how we can reach you. + +We reply within five business days. When we confirm a problem, we rate its +severity and fix it on the timeline that severity sets. + +SCADABLE does not run a bug bounty program. + +## Supported versions + +Only the default branch is supported. A fix is made there and reaches users in +the next release or deploy.