Skip to content

Add org-wide community health files and license - #1

Merged
stxkxs merged 1 commit into
mainfrom
chore/community-health-files
Aug 19, 2026
Merged

stxkxs merged 1 commit into
mainfrom
chore/community-health-files

Conversation

@stxkxs

@stxkxs stxkxs commented Aug 19, 2026

Copy link
Copy Markdown
Member

Closes the community-health gap found in the 2026-08-18 maintenance sweep. citature/.github carried only the org profile — no disclosure path, no license, no contribution guidance.

What's here

File Notes
SECURITY.md Private disclosure via GitHub advisories. Scope written for citature specifically.
CONTRIBUTING.md PR-only workflow + a data-provenance bar generic templates don't cover.
CODE_OF_CONDUCT.md Contributor Covenant 1.4, plus an entity-level clause.
LICENSE Apache-2.0, matching the estate convention.
README.md Repo-level orientation, distinct from profile/README.md.

Two things worth a reviewer's attention

1. SECURITY.md leads with integrity, not confidentiality. citature's data is public by law and holds no secrets, so a generic "report vulnerabilities" template would have pointed at the wrong threat surface. The policy names provenance tampering — forging a citation, retrieval timestamp, or source locator — as the highest-severity class, because re-fetchability from the upstream government source is the product contract. Upstream record errors are explicitly ruled out of scope as coverage caveats.

2. The reach limitation is stated in the file, not just in this PR. GitHub applies default health files to public repositories only. citature's only other repo is private, so today the practical reach is this repository alone. That's a real limit and SECURITY.md says so in its own text rather than implying org-wide coverage it doesn't have. The files land now so the path exists when that changes.

Verification

  • Apache-2.0 text pulled from the GitHub licenses API, not hand-written; copyright line matches nanohype/.github and rackctl/.github exactly.
  • All external links in the new files resolve.
  • No changes to profile/README.md in this PR — the profile content findings are handled separately.

Part of the maintenance sweep. Sibling PRs cover CI, the profile restructure, and the data-claim provenance fix.

citature/.github carried only the org profile. This adds the community
health files GitHub reads from a .github repository, matching the layout
and tone used across the estate's other org repos.

─────────────────────────── Files ───────────────────────────

SECURITY.md — private disclosure via GitHub security advisories, with a
scope section written for what citature actually is. The data is public
by law and holds no secrets, so the policy leads with integrity and
provenance rather than confidentiality: forging a citation, timestamp, or
source locator is named as the highest-severity bug class, since
re-fetchability from the upstream government source is the product's
entire contract. Also scopes the MCP server, actor/ingestion code, and
the release supply chain, and explicitly rules upstream record content
out of scope as a coverage caveat rather than a vulnerability. Carries a
personal-data clause: a surface that resolves or profiles a natural
person beyond the public record is a security issue, not a feature.

CONTRIBUTING.md — PR-only workflow, squash merges preserving the authored
message, CI green before merge. Adds a data-specific bar that generic
templates don't cover: every claim keeps its locator, cite the source of
record and never an aggregator, date anything that rots, and treat
coverage caveats as output rather than footnotes.

CODE_OF_CONDUCT.md — Contributor Covenant 1.4, with one project-specific
addition: the community holds the same entity-level line the product
does, so the issue tracker is not to be used to target or profile a
private individual.

LICENSE — Apache-2.0, "Copyright 2026 stxkxs", matching the convention
already used by nanohype/.github, rackctl/.github, and the estate's
public repositories.

README.md — repository-level orientation, distinct from profile/README.md
which renders on the org page.

───────────────────────── Reach note ─────────────────────────

GitHub applies default health files to PUBLIC repositories only. The only
other repository in the org today is private, so the immediate reach is
this repository. The files land now so the disclosure path already exists
when that changes; SECURITY.md states this limitation in its own text
rather than leaving it implicit.

Co-authored-by: stxkxsbot <275011021+stxkxsbot@users.noreply.github.com>
@stxkxs
stxkxs force-pushed the chore/community-health-files branch from 5cb9f00 to d1ed633 Compare August 19, 2026 06:46
@stxkxs
stxkxs merged commit 5ef5e4a into main Aug 19, 2026
2 checks passed
@stxkxs
stxkxs deleted the chore/community-health-files branch August 19, 2026 06:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant