Add org-wide community health files and license - #1
Merged
Merged
Conversation
This was referenced Aug 19, 2026
citature/.github carried only the org profile. This adds the community health files GitHub reads from a .github repository, matching the layout and tone used across the estate's other org repos. ─────────────────────────── Files ─────────────────────────── SECURITY.md — private disclosure via GitHub security advisories, with a scope section written for what citature actually is. The data is public by law and holds no secrets, so the policy leads with integrity and provenance rather than confidentiality: forging a citation, timestamp, or source locator is named as the highest-severity bug class, since re-fetchability from the upstream government source is the product's entire contract. Also scopes the MCP server, actor/ingestion code, and the release supply chain, and explicitly rules upstream record content out of scope as a coverage caveat rather than a vulnerability. Carries a personal-data clause: a surface that resolves or profiles a natural person beyond the public record is a security issue, not a feature. CONTRIBUTING.md — PR-only workflow, squash merges preserving the authored message, CI green before merge. Adds a data-specific bar that generic templates don't cover: every claim keeps its locator, cite the source of record and never an aggregator, date anything that rots, and treat coverage caveats as output rather than footnotes. CODE_OF_CONDUCT.md — Contributor Covenant 1.4, with one project-specific addition: the community holds the same entity-level line the product does, so the issue tracker is not to be used to target or profile a private individual. LICENSE — Apache-2.0, "Copyright 2026 stxkxs", matching the convention already used by nanohype/.github, rackctl/.github, and the estate's public repositories. README.md — repository-level orientation, distinct from profile/README.md which renders on the org page. ───────────────────────── Reach note ───────────────────────── GitHub applies default health files to PUBLIC repositories only. The only other repository in the org today is private, so the immediate reach is this repository. The files land now so the disclosure path already exists when that changes; SECURITY.md states this limitation in its own text rather than leaving it implicit. Co-authored-by: stxkxsbot <275011021+stxkxsbot@users.noreply.github.com>
stxkxs
force-pushed
the
chore/community-health-files
branch
from
August 19, 2026 06:46
5cb9f00 to
d1ed633
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the community-health gap found in the 2026-08-18 maintenance sweep.
citature/.githubcarried only the org profile — no disclosure path, no license, no contribution guidance.What's here
SECURITY.mdCONTRIBUTING.mdCODE_OF_CONDUCT.mdLICENSEREADME.mdprofile/README.md.Two things worth a reviewer's attention
1. SECURITY.md leads with integrity, not confidentiality. citature's data is public by law and holds no secrets, so a generic "report vulnerabilities" template would have pointed at the wrong threat surface. The policy names provenance tampering — forging a citation, retrieval timestamp, or source locator — as the highest-severity class, because re-fetchability from the upstream government source is the product contract. Upstream record errors are explicitly ruled out of scope as coverage caveats.
2. The reach limitation is stated in the file, not just in this PR. GitHub applies default health files to public repositories only. citature's only other repo is private, so today the practical reach is this repository alone. That's a real limit and
SECURITY.mdsays so in its own text rather than implying org-wide coverage it doesn't have. The files land now so the path exists when that changes.Verification
nanohype/.githubandrackctl/.githubexactly.profile/README.mdin this PR — the profile content findings are handled separately.Part of the maintenance sweep. Sibling PRs cover CI, the profile restructure, and the data-claim provenance fix.