Skip to content

docs: add security policy#11876

Merged
kdy1 merged 1 commit into
swc-project:mainfrom
kdy1:kdy1/add-security-policy
May 21, 2026
Merged

docs: add security policy#11876
kdy1 merged 1 commit into
swc-project:mainfrom
kdy1:kdy1/add-security-policy

Conversation

@kdy1
Copy link
Copy Markdown
Member

@kdy1 kdy1 commented May 21, 2026

Description:

Adds a root-level SECURITY.md for SWC. The policy documents supported versions, private vulnerability reporting through kdy.1997.dev@gmail.com, SWC's security model as a build tool rather than a SaaS or multi-tenant sandbox, and the intended in-scope and out-of-scope report categories.

This gives users a clear private reporting path and sets expectations for integrators that accept untrusted input.

BREAKING CHANGE:

None.

Related issue (if exists):

None.

@kdy1 kdy1 requested a review from a team as a code owner May 21, 2026 01:49
@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented May 21, 2026

⚠️ No Changeset found

Latest commit: 06af650

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@kdy1 kdy1 changed the title [codex] docs: add security policy docs: add security policy May 21, 2026
@kdy1 kdy1 merged commit 6c43c2d into swc-project:main May 21, 2026
42 checks passed
@kdy1 kdy1 deleted the kdy1/add-security-policy branch May 21, 2026 01:50
@github-actions github-actions Bot added this to the Planned milestone May 21, 2026
@codspeed-hq
Copy link
Copy Markdown

codspeed-hq Bot commented May 21, 2026

Merging this PR will not alter performance

✅ 219 untouched benchmarks
⏩ 31 skipped benchmarks1


Comparing kdy1:kdy1/add-security-policy (06af650) with main (aa5b539)

Open in CodSpeed

Footnotes

  1. 31 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant