Skip to content

chore: Add .github/SECURITY.md - #5165

Merged
gundalow merged 1 commit into
ansible:mainfrom
gundalow:rollout/add-security-md
Aug 26, 2026
Merged

gundalow merged 1 commit into
ansible:mainfrom
gundalow:rollout/add-security-md

Conversation

@gundalow

@gundalow gundalow commented Aug 25, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Add a standardised SECURITY.md to .github/ so security reporting instructions are discoverable across all Ansible repositories.

The canonical source is ansible-community/project-template/SECURITY.md.

The file has already been reviewed

See Forum Post for context

Summary by CodeRabbit

  • Documentation
    • Expanded the security policy with detailed vulnerability-reporting instructions.
    • Added required report details and expected response timelines.
    • Clarified supported backports and linked to the Ansible security policy.
    • Added an EU Cyber Resilience Act steward statement and contact information.

@gundalow
gundalow requested a review from a team as a code owner August 25, 2026 16:12
@gundalow
gundalow enabled auto-merge (squash) August 25, 2026 16:12
@gundalow gundalow changed the title Add .github/SECURITY.md feat: Add .github/SECURITY.md Aug 25, 2026
@gundalow
gundalow force-pushed the rollout/add-security-md branch from b2fac04 to a209940 Compare August 25, 2026 17:02
@gundalow gundalow changed the title feat: Add .github/SECURITY.md chore: Add .github/SECURITY.md Aug 25, 2026
@github-actions github-actions Bot added the feat label Aug 25, 2026
@coderabbitai

coderabbitai Bot commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 14454da6-56c1-4723-8077-4d5a2604ac78

📥 Commits

Reviewing files that changed from the base of the PR and between e6ec973 and a209940.

📒 Files selected for processing (1)
  • .github/SECURITY.md

Included review availability: Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The security policy now defines email-only vulnerability reporting, required report contents, response timelines, limited backports, the Ansible security policy, and Red Hat’s EU Cyber Resilience Act steward contact.

Changes

Security Policy

Layer / File(s) Summary
Security policy guidance
.github/SECURITY.md
The policy adds vulnerability reporting requirements, response timelines, limited backport guidance, an Ansible security policy link, and Red Hat steward contact information.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to a2099

This is a localized documentation update, and no actionable merge-blocking risk remains after normal checks and review.

Suggested reviewers: alisonlhart

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the addition of .github/SECURITY.md, which is the main change.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gundalow
gundalow merged commit 9049142 into ansible:main Aug 26, 2026
22 checks passed
ivanch added a commit to ivanch/haven that referenced this pull request Sep 27, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ansible-lint](https://github.com/ansible/ansible-lint) ([changelog](https://github.com/ansible/ansible-lint/releases)) | minor | `==26.6.0` → `==26.9.0` |

---

### Release Notes

<details>
<summary>ansible/ansible-lint (ansible-lint)</summary>

### [`v26.9.0`](https://github.com/ansible/ansible-lint/releases/tag/v26.9.0)

[Compare Source](ansible/ansible-lint@v26.8.0...v26.9.0)

#### Features

- feat: support `example` section in file `meta/argument_specs.yml` ([#&#8203;5164](ansible/ansible-lint#5164)) [@&#8203;berndfinger](https://github.com/berndfinger)

#### Fixes

- fix: resolve short mock modules during syntax check ([#&#8203;5149](ansible/ansible-lint#5149)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: propagate `extra_vars` to `import_playbook` syntax check ([#&#8203;5148](ansible/ansible-lint#5148)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: resolve nested `include_tasks` relative paths ([#&#8203;5159](ansible/ansible-lint#5159)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: resolve `include_tasks` paths from playbook dir ([#&#8203;5184](ansible/ansible-lint#5184)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: apply profile-level skip list during linting ([#&#8203;5151](ansible/ansible-lint#5151)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: honor `warn_list` after `--fix` rewrites task names ([#&#8203;5085](ansible/ansible-lint#5085)) [@&#8203;santosh7676](https://github.com/santosh7676)
- fix: mock\_modules clobbering collections and args false positives ([#&#8203;5157](ansible/ansible-lint#5157)) [@&#8203;djdanielsson](https://github.com/djdanielsson)
- fix: inject plain-name mock roles path regardless of `--offline` ([#&#8203;5183](ansible/ansible-lint#5183)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: warn users when directory expansion discovers new files ([#&#8203;5158](ansible/ansible-lint#5158)) [@&#8203;rockygeekz](https://github.com/rockygeekz)
- fix: skip auto-fix `no-jinja-when` on string-embedded jinja ([#&#8203;5103](ansible/ansible-lint#5103)) [@&#8203;f1047](https://github.com/f1047)
- fix: do not warn when Jinja block indent is only trim-marker noise ([#&#8203;5153](ansible/ansible-lint#5153)) [@&#8203;DSeaStar](https://github.com/DSeaStar)
- fix: preserve blank lines after flow collections ([#&#8203;5178](ansible/ansible-lint#5178)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: add `validate_argspec` to play schema ([#&#8203;5187](ansible/ansible-lint#5187)) [@&#8203;sameeralam3127](https://github.com/sameeralam3127)
- fix: use ThreadPoolExecutor for syntax check workers ([#&#8203;5173](ansible/ansible-lint#5173)) [@&#8203;rockygeekz](https://github.com/rockygeekz)
- fix: drop ruamel.yaml.clib ([#&#8203;5163](ansible/ansible-lint#5163)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix(deps): upgrade gitpython 3.1.57 to 3.1.59 ([#&#8203;5152](ansible/ansible-lint#5152)) [@&#8203;rockygeekz](https://github.com/rockygeekz)
- fix: upgrade black to >=25.2.0 to address CVE-2026-32274 ([#&#8203;5166](ansible/ansible-lint#5166)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: raise cryptography floor and bump js-yaml for Guardian prod vulns ([#&#8203;5174](ansible/ansible-lint#5174)) [@&#8203;rockygeekz](https://github.com/rockygeekz)

#### Performance

- perf: cache `get_deps_versions()` result ([#&#8203;5113](ansible/ansible-lint#5113)) [@&#8203;BlackDark](https://github.com/BlackDark)

#### Maintenance

- chore: Add `.github/SECURITY.md` ([#&#8203;5165](ansible/ansible-lint#5165)) [@&#8203;gundalow](https://github.com/gundalow)
- chore(deps): update all dependencies and pep621 ([#&#8203;5138](ansible/ansible-lint#5138), [#&#8203;5154](ansible/ansible-lint#5154), [#&#8203;5155](ansible/ansible-lint#5155), [#&#8203;5160](ansible/ansible-lint#5160), [#&#8203;5161](ansible/ansible-lint#5161), [#&#8203;5172](ansible/ansible-lint#5172), [#&#8203;5175](ansible/ansible-lint#5175), [#&#8203;5176](ansible/ansible-lint#5176)) @&#8203;[renovate\[bot\]](https://github.com/apps/renovate)

#### What's Changed

- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5138](ansible/ansible-lint#5138)
- fix: resolve short mock modules during syntax check by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5149](ansible/ansible-lint#5149)
- fix(deps): upgrade gitpython 3.1.57 to 3.1.59 by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5152](ansible/ansible-lint#5152)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5155](ansible/ansible-lint#5155)
- fix: propagate extra\_vars to import\_playbook syntax check by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5148](ansible/ansible-lint#5148)
- fix: warn users when directory expansion discovers new files by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5158](ansible/ansible-lint#5158)
- fix: resolve nested include\_tasks relative paths by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5159](ansible/ansible-lint#5159)
- fix: apply profile-level skip list during linting by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5151](ansible/ansible-lint#5151)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5154](ansible/ansible-lint#5154)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5160](ansible/ansible-lint#5160)
- fix: skip auto-fix no-jinja-when on string-embedded jinja by [@&#8203;f1047](https://github.com/f1047) in [#&#8203;5103](ansible/ansible-lint#5103)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5161](ansible/ansible-lint#5161)
- fix: do not warn when Jinja block indent is only trim-marker noise by [@&#8203;DSeaStar](https://github.com/DSeaStar) in [#&#8203;5153](ansible/ansible-lint#5153)
- chore: Add .github/SECURITY.md by [@&#8203;gundalow](https://github.com/gundalow) in [#&#8203;5165](ansible/ansible-lint#5165)
- fix: upgrade black to >=25.2.0 to address CVE-2026-32274 by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5166](ansible/ansible-lint#5166)
- Fix/drop ruamel yaml clib fresh by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5163](ansible/ansible-lint#5163)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5172](ansible/ansible-lint#5172)
- fix: honor warn\_list after --fix rewrites task names  by [@&#8203;santosh7676](https://github.com/santosh7676) in [#&#8203;5085](ansible/ansible-lint#5085)
- feat: support 'example' section in file meta/argument\_specs.yml by [@&#8203;berndfinger](https://github.com/berndfinger) in [#&#8203;5164](ansible/ansible-lint#5164)
- fix: use ThreadPoolExecutor for syntax check workers by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5173](ansible/ansible-lint#5173)
- fix: mock\_modules clobbering collections and args false positives by [@&#8203;djdanielsson](https://github.com/djdanielsson) in [#&#8203;5157](ansible/ansible-lint#5157)
- fix: raise cryptography floor and bump js-yaml for Guardian prod vulns by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5174](ansible/ansible-lint#5174)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5176](ansible/ansible-lint#5176)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5175](ansible/ansible-lint#5175)
- fix: preserve blank lines after flow collections by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5178](ansible/ansible-lint#5178)
- perf: cache get\_deps\_versions() result by [@&#8203;BlackDark](https://github.com/BlackDark) in [#&#8203;5113](ansible/ansible-lint#5113)
- fix: inject plain-name mock roles path regardless of --offline by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5183](ansible/ansible-lint#5183)
- fix: resolve include\_tasks paths from playbook dir by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5184](ansible/ansible-lint#5184)
- fix: add validate\_argspec to play schema by [@&#8203;sameeralam3127](https://github.com/sameeralam3127) in [#&#8203;5187](ansible/ansible-lint#5187)

#### New Contributors

- [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) made their first contribution in [#&#8203;5149](ansible/ansible-lint#5149)
- [@&#8203;f1047](https://github.com/f1047) made their first contribution in [#&#8203;5103](ansible/ansible-lint#5103)
- [@&#8203;DSeaStar](https://github.com/DSeaStar) made their first contribution in [#&#8203;5153](ansible/ansible-lint#5153)
- [@&#8203;berndfinger](https://github.com/berndfinger) made their first contribution in [#&#8203;5164](ansible/ansible-lint#5164)
- [@&#8203;BlackDark](https://github.com/BlackDark) made their first contribution in [#&#8203;5113](ansible/ansible-lint#5113)
- [@&#8203;sameeralam3127](https://github.com/sameeralam3127) made their first contribution in [#&#8203;5187](ansible/ansible-lint#5187)

**Full Changelog**: <ansible/ansible-lint@v26.8.0...v26.9.0>

### [`v26.8.0`](https://github.com/ansible/ansible-lint/releases/tag/v26.8.0)

[Compare Source](ansible/ansible-lint@v26.6.0...v26.8.0)

#### What's Changed

- Fix/sonarcloud unbounded recursion complexity by [@&#8203;sathyapramod](https://github.com/sathyapramod) in [#&#8203;5098](ansible/ansible-lint#5098)
- feat: honor ANSIBLE\_VAULT\_PASSWORD\_FILE for vault decryption by [@&#8203;JohnLahr](https://github.com/JohnLahr) in [#&#8203;5019](ansible/ansible-lint#5019)
- fix: jinja\[spacing] rule creating invalid syntax for minus modifiers by [@&#8203;Dotify71](https://github.com/Dotify71) in [#&#8203;5102](ansible/ansible-lint#5102)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5081](ansible/ansible-lint#5081)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5082](ansible/ansible-lint#5082)
- fix: remove stale words from cspell dictionary by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5109](ansible/ansible-lint#5109)
- chore(deps): bump schemas npm packages for Dependabot CVEs by [@&#8203;sudhirverma](https://github.com/sudhirverma) in [#&#8203;5114](ansible/ansible-lint#5114)
- fix(security): update dependencies \[SECURITY] by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5111](ansible/ansible-lint#5111)
- fix: address SonarCloud new code violations by [@&#8203;sudhirverma](https://github.com/sudhirverma) in [#&#8203;5116](ansible/ansible-lint#5116)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5121](ansible/ansible-lint#5121)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5122](ansible/ansible-lint#5122)
- fix(deps): exclude ansible-core 2.17.x (CVE-2026-11332) by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5123](ansible/ansible-lint#5123)
- fix: expose ansible-galaxy on the uv tool-install path by [@&#8203;jeffcpullen](https://github.com/jeffcpullen) in [#&#8203;5124](ansible/ansible-lint#5124)
- fix: var-naming for register projections by [@&#8203;0xTaoZ](https://github.com/0xTaoZ) in [#&#8203;5110](ansible/ansible-lint#5110)
- chore: Adding OpenWrt 25.12 as platform by [@&#8203;sscheib](https://github.com/sscheib) in [#&#8203;5132](ansible/ansible-lint#5132)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5134](ansible/ansible-lint#5134)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5133](ansible/ansible-lint#5133)
- fix: add timeout to release-check urlopen() call by [@&#8203;cooperlees](https://github.com/cooperlees) in [#&#8203;5128](ansible/ansible-lint#5128)
- fix: respect ANSIBLE\_HOME env var for cache dir selection ([#&#8203;5806](https://github.com/ansible/ansible-lint/issues/5806)) by [@&#8203;Jkhall81](https://github.com/Jkhall81) in [#&#8203;5105](ansible/ansible-lint#5105)
- fix: deduplicate ANSIBLE\_HOME isolation check by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5140](ansible/ansible-lint#5140)
- fix(security): update dependencies \[SECURITY] by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5141](ansible/ansible-lint#5141)
- fix: do not require role prefix for ansible\_ connection variables by [@&#8203;Sanjays2402](https://github.com/Sanjays2402) in [#&#8203;5130](ansible/ansible-lint#5130)
- Adding missing FreeBSD versions. by [@&#8203;jmpalacios](https://github.com/jmpalacios) in [#&#8203;5143](ansible/ansible-lint#5143)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5139](ansible/ansible-lint#5139)
- fix: prepend runtime cache dir to collections paths ([#&#8203;5137](ansible/ansible-lint#5137)) by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5145](ansible/ansible-lint#5145)

#### New Contributors

- [@&#8203;sathyapramod](https://github.com/sathyapramod) made their first contribution in [#&#8203;5098](ansible/ansible-lint#5098)
- [@&#8203;JohnLahr](https://github.com/JohnLahr) made their first contribution in [#&#8203;5019](ansible/ansible-lint#5019)
- [@&#8203;jeffcpullen](https://github.com/jeffcpullen) made their first contribution in [#&#8203;5124](ansible/ansible-lint#5124)
- [@&#8203;0xTaoZ](https://github.com/0xTaoZ) made their first contribution in [#&#8203;5110](ansible/ansible-lint#5110)
- [@&#8203;cooperlees](https://github.com/cooperlees) made their first contribution in [#&#8203;5128](ansible/ansible-lint#5128)
- [@&#8203;Sanjays2402](https://github.com/Sanjays2402) made their first contribution in [#&#8203;5130](ansible/ansible-lint#5130)
- [@&#8203;jmpalacios](https://github.com/jmpalacios) made their first contribution in [#&#8203;5143](ansible/ansible-lint#5143)

**Full Changelog**: <ansible/ansible-lint@v26.6.0...v26.8.0>

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuNyIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy43IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

---------

Co-authored-by: Renovate Bot <bot@renovateapp.com>
Reviewed-on: https://git.ivanch.me/ivanch/haven/pulls/17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

2 participants