Skip to content

docs: give every repo a reporting channel that actually exists - #54

Merged
webdevsamran merged 1 commit into
mainfrom
docs/contact-channels
Sep 7, 2026
Merged

docs: give every repo a reporting channel that actually exists#54
webdevsamran merged 1 commit into
mainfrom
docs/contact-channels

Conversation

@webdevsamran

Copy link
Copy Markdown
Owner

Two of the four Code of Conduct files in this family of projects pointed at GitHub features that are not real:

  • devrepro-doctor: report "via GitHub private message" — GitHub has no private messaging.
  • local-ai-hardware-bench: report by "opening a private issue tagged conduct" — GitHub has private vulnerability reports; it has no private issues.

api-verity-lab gave a profile URL rather than a contact channel. Only tooltrace-bench named an address that works.

Someone reporting harassment is the worst possible person to hand a dead end, so all four now carry the same wording: the maintainer's noreply address plus GitHub's real report-abuse form.

The worse one, found while checking the above

All four SECURITY.md files direct reporters to GitHub's private vulnerability reporting — and it was disabled on all four repositories. Every documented security-disclosure path in this family of projects led to a page the reporter could not use. It is enabled now; that is a repository setting, so it does not appear in this diff.

SLAs

The disclosure SLAs disagreed for the same solo maintainer: 72h, 72h + 7d, 7d, and 7d + 30d. Standardized on 7 days to acknowledge, 30 to update — the most conservative of the four — and the document now says why: promising 72 hours when nobody is on call is a promise, not a policy.

What keeps it fixed

test_contact_channels_exist.py asserts the working address and report-abuse form are present, that SECURITY.md still names private vulnerability reporting and still warns against public issues, and that no document mentions "private message", "private issue" or "report-user functionality" again. Verified by reintroducing the devrepro-doctor wording and watching it fail.

Two of the four Code of Conduct files pointed at GitHub features that are not
real:

- devrepro-doctor: report "via GitHub private message". GitHub has no private
  messaging.
- local-ai-hardware-bench: report by "opening a private issue tagged
  `conduct`". GitHub has private *vulnerability reports*; it has no private
  issues.

api-verity-lab gave a profile URL rather than a contact channel. Only
tooltrace-bench named an address that works. Someone reporting harassment is
the worst possible person to hand a dead end, so all four now carry the same
wording: the maintainer's noreply address plus GitHub's real report-abuse form.

Worse, and found while checking the above: all four SECURITY.md files direct
reporters to GitHub's private vulnerability reporting, and it was **disabled on
all four repositories**. Every documented security-disclosure path in this
family of projects led to a page the reporter could not use. It is enabled now
(a repository setting, so not visible in this diff).

The disclosure SLAs also disagreed for the same solo maintainer -- 72h, 72h+7d,
7d, and 7d+30d. Standardized on 7 days to acknowledge and 30 to update, the
most conservative of the four, and said plainly why: promising 72 hours when
nobody is on call is a promise, not a policy.

tests/test_contact_channels_exist.py pins this. It asserts the working address
and the report-abuse form are present, that SECURITY.md still names private
vulnerability reporting and still warns against public issues, and -- the point
of the exercise -- that no document mentions "private message", "private issue"
or "report-user functionality" again. Verified by reintroducing the
devrepro-doctor wording and watching it fail.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@webdevsamran
webdevsamran merged commit e70fbbd into main Sep 7, 2026
12 checks passed
@webdevsamran
webdevsamran deleted the docs/contact-channels branch September 7, 2026 19:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant