Skip to content

⚠️ Warning: update public SECURITY.md reporting instructions#446

Merged
coliff merged 2 commits intomainfrom
chore/public-security-reporting-warning-2026-04-30
May 1, 2026
Merged

⚠️ Warning: update public SECURITY.md reporting instructions#446
coliff merged 2 commits intomainfrom
chore/public-security-reporting-warning-2026-04-30

Conversation

@jeff-at-trimble
Copy link
Copy Markdown
Contributor

⚠️ Warning: this is a proactive compliance update ahead of trimble-oss/oss-overseer#170.

Why this PR exists

A public policy update is queued in oss-overseer that will require public repositories to do both of the following in SECURITY.md:

  1. Include the Trimble public security form URL:

    https://www.trimble.com/en/our-commitment/responsible-business/data-privacy-and-security/report-cybersecurity-issues/form
    
  2. Stop using cybersecurity@trimble.com, which is for internal use only.

What this PR changes

  • updates the Reporting a Vulnerability section to point to the approved public form
  • removes the internal-only email address
  • leaves the rest of the file unchanged

Why this matters

If trimble-oss/oss-overseer#170 merges before this repo updates SECURITY.md, the next public audit will report a new MUST violation for this repository.

This PR is meant as an early warning and a low-noise fix before that rollout happens.

Proactive update ahead of trimble-oss/oss-overseer#170.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@jeff-at-trimble jeff-at-trimble requested a review from coliff as a code owner April 30, 2026 17:01
@trimble-oss trimble-oss deleted a comment from github-actions Bot May 1, 2026
@coliff coliff merged commit bd84595 into main May 1, 2026
7 of 9 checks passed
@coliff coliff deleted the chore/public-security-reporting-warning-2026-04-30 branch May 1, 2026 06:41
@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 1, 2026

Super-linter summary

Language Validation result
GITLEAKS Pass ✅
GIT_MERGE_CONFLICT_MARKERS Pass ✅
MARKDOWN Pass ✅
MARKDOWN_PRETTIER Pass ✅
PRE_COMMIT Pass ✅
SPELL_CODESPELL Pass ✅
TRIVY Pass ✅

All files and directories linted successfully

For more information, see the GitHub Actions workflow run

Powered by Super-linter

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants