Skip to content

Document fleetdm/security repo in handbook - #51144

Merged
lukeheath merged 4 commits into
mainfrom
lukeheath/document-security-repo
Aug 13, 2026
Merged

Document fleetdm/security repo in handbook#51144
lukeheath merged 4 commits into
mainfrom
lukeheath/document-security-repo

Conversation

@lukeheath

@lukeheath lukeheath commented Aug 13, 2026

Copy link
Copy Markdown
Member

Fleet now tracks application security reports (vulnerabilities, pen test findings, responsible disclosures) in the dedicated private fleetdm/security repo instead of fleetdm/confidential, so security work can be shared with outside security consultants without exposing broader confidential matters (customers, people ops, finance).

This PR updates the handbook to match:

  • Handbook: Engineering → Handle a security report — intake now points at fleetdm/security with a direct link to the standardized security report issue form, notes that security-labeled issues are automatically added to the :help-security project, and states the boundary rule: customer-identifying context stays in fleetdm/confidential and is linked, never copied.
  • Handbook: Engineering → Stage a fix for a security report — references to the confidential repo/ticket updated to fleetdm/security.

🤖 Generated with Claude Code

Security report intake moved from fleetdm/confidential to the dedicated
private fleetdm/security repo. Update the engineering security report
process and add a note to levels of confidentiality, with direct links
to the standardized security report issue form.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings August 13, 2026 14:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@fleet-release
fleet-release requested a review from ireedy August 13, 2026 14:51
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
fleet-release
fleet-release previously approved these changes Aug 13, 2026
Comment thread handbook/engineering/README.md Outdated
@lukeheath
lukeheath merged commit e17ad33 into main Aug 13, 2026
10 checks passed
@lukeheath
lukeheath deleted the lukeheath/document-security-repo branch August 13, 2026 15:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants