Skip to content

FTUE: issue templates — security → SECURITY.md (#31) - #40

Merged
CodeSolutionsLLC merged 2 commits into
mainfrom
feat/31-issue-templates
Sep 27, 2026
Merged

CodeSolutionsLLC merged 2 commits into
mainfrom
feat/31-issue-templates

Conversation

@CodeSolutionsLLC

@CodeSolutionsLLC CodeSolutionsLLC commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Thanks for the pull request. See CONTRIBUTING.md for how changes land on main.

Summary

Add public issue forms so bug reports, documentation notes, and other product discussion have a place to land. Security reports stay off public issues: the chooser links to SECURITY.md, which asks for a private email to security@codesolutionsllc.com.

Related issue

Closes #31

Files

  • .github/ISSUE_TEMPLATE/config.yml — blank issues off; security contact link to SECURITY.md
  • .github/ISSUE_TEMPLATE/bug.yml — what happened, expected, steps to reproduce, optional environment, additional context
  • .github/ISSUE_TEMPLATE/docs.yml — docs page / skill / playbook, what's wrong or missing, suggested fix
  • .github/ISSUE_TEMPLATE/other.yml — short catch-all for non-bug, non-docs discussion

Each form tells reporters not to include secrets, PATs, private config, or exploit writeups, and to use SECURITY.md for vulnerabilities. .github/pull_request_template.md is unchanged.

How to verify

Issue forms are read from the default branch, so the chooser updates after merge to main.

  1. Open New issue. The chooser lists Bug report, Documentation, and Other.
  2. Report a security vulnerability is visible and opens https://github.com/CodeSolutionsLLC/cs-stack/blob/main/SECURITY.md. The link text says to report privately (security@codesolutionsllc.com), not to open a public issue, and not to paste secrets, tokens, or exploit details.
  3. Open each form and confirm the fields above, including the private-reporting note.

Before merge, review those four files in this diff.

Checklist

  • Evidence recorded. Summary and how to verify are filled in (commands, tests, or links). See verify and playbooks/verify.md.
  • CI green. Required checks on this pull request are passing, including validate.
  • No secrets. The pull request body and diff have no tokens, PATs, private config, or exploit details. Report security issues privately — SECURITY.md.
  • CODEOWNERS human merge (no self-merge). Authors wait for an independent human review and merge. Reviewers are listed in .github/CODEOWNERS. See no-self-merge and human-gate.
  • Public language safe. No private credentials, internal roster names, or private links.
Open in Web Open in Cursor 

Public bug, docs, and other forms. The issue chooser links vulnerabilities to SECURITY.md and the private security email instead of a public issue.

Co-authored-by: Code Solutions LLC <CodeSolutionsLLC@users.noreply.github.com>

Copy link
Copy Markdown
Owner Author

Human VERIFY PASS (Computer)

Acceptance vs PR #40 @ 9bc1565:

Still draft. Awaiting Code merge.

@CodeSolutionsLLC
CodeSolutionsLLC merged commit 8545e8e into main Sep 27, 2026
3 checks passed
@CodeSolutionsLLC
CodeSolutionsLLC deleted the feat/31-issue-templates branch September 27, 2026 22:57

Copy link
Copy Markdown
Owner Author

MERGED — PR #40 → 8545e8e

Squash-merged with maintainer-directed admin recipe. Protection restored. Issue #31 auto-closed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

FTUE: issue template(s) — security reports → SECURITY.md

2 participants