Skip to content

Guardrails / docs

Repository documents how to report a vulnerability ​

docs/security-policy@v1

The repository has a SECURITY.md saying where to report a security problem.

Iddocs/security-policy
Versionv1
Categorydocs
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsfiles

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
filesPresence, size and line counts of the well known files a repository is expected to carry, plus any extra path the guardrail asks for.path

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "docs/security-policy@v1",
              "severity": "warning",
              "with": {
                  "path": "SECURITY.md",
                  "minLines": "3",
                  "contact": "true"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
pathPath to the security policy, relative to the directory the CLI runs in.SECURITY.mdGUARDRAIL_INPUT_PATH
minLinesHow many non-blank lines it needs before it counts as written.3GUARDRAIL_INPUT_MINLINES
contactWhether the policy must include a way to get in touch, either an email address or a URL.trueGUARDRAIL_INPUT_CONTACT

How to fix ​

Add a SECURITY.md at the repository root, or under .github/, saying where to report a vulnerability and how quickly a reporter can expect a response:

markdown
# Security

Report a vulnerability to security@company.com. We acknowledge within two working days.

GitHub links this file from the repository's Security tab and from the advisory form. Without it, a researcher who finds something has nowhere to send it except a public issue, and that is a disclosure, not a report.

More in docs ​

  • docs/agent-instructions. The repository has an instruction file for coding agents, long enough to say something and short enough to be read in full.
  • docs/changelog. The repository has a changelog, so what changed between two releases is written down instead of pieced together from commits.
  • docs/code-of-conduct. The repository has a CODE_OF_CONDUCT.md, so the standard contributors are held to, and who enforces it, is written down.
  • docs/contributing. The repository has a CONTRIBUTING.md explaining how a change is proposed, built and reviewed.
  • docs/license-present. The repository has a licence file, so what people may do with the code is written down, not assumed.
  • docs/readme. The repository has a README that says more than just its title.

All 7 docs guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412