Skip to content

Commit e089a15

Browse files
iamdadmininnocenzi
andauthored
docs: apply grammar changes as requested
Co-authored-by: Enzo Innocenzi <enzo@innocenzi.dev>
1 parent fe3d5b7 commit e089a15

1 file changed

Lines changed: 13 additions & 13 deletions

File tree

SECURITY.md

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,35 +1,35 @@
1-
# TempestPHP Security Policy
1+
# Tempest security policy
22

3-
## Reporting a Security Issue
3+
## Reporting a security issue
44

5-
If you think you have found a Security Issue within one or more of the TempestPHP repositories, don't use the Issues and don't publish a PR with proof of concept. In the first instance, report issues using [GitHub's security advisory reporting mechanism](https://github.com/tempestphp/tempest-framework/security/advisories/new), with as much information as you can provide, ideally including steps-to-recreate. Security reports submitted on this page are forwarded to the core maintainers, only.
5+
If you think you have found a security issue within Tempest, don't create a GitHub issue and don't publish a pull request with proof of concept. In the first instance, report issues using [GitHub's security advisory reporting mechanism](https://github.com/tempestphp/tempest-framework/security/advisories/new), with as much information as you can provide, ideally including steps-to-recreate. Security reports submitted on this page are forwarded to the core maintainers only.
66

7-
The core maintainers will determine whether this is classified as a Security Issue, and address it accordingly, or whether it is classified as a regular bug, and may ask you to raise a GitHub Issue instead, at this time.
7+
The core maintainers will determine whether this is classified as a security issue, and address it accordingly, or whether it is classified as a regular bug, and may ask you to raise a GitHub issue instead, at this time.
88

9-
## Resolution Process
9+
## Resolution process
1010

11-
The core maintainers will aim to acknowledge and validate any reported Security Issue promptly.
11+
The core maintainers will aim to acknowledge and validate any reported security issue promptly.
1212

13-
Following the validation of a Security Issue, the core maintainers will broadly:
13+
Following the validation of a security issue, the core maintainers will broadly:
1414

1515
1. Work on a patch and commit it to the repository via GitHub following the usual processes.
1616

1717
2. Issue a release containing the security release.
1818

1919
3. Consider offering a Rector automated fix within the release, where appropriate.
2020

21-
4. Notify all subscribed TempestPHP parties via the usual channels (discord, blog, etc) that the updated is published.
21+
4. Notify all subscribed Tempest parties via the usual channels (discord, blog, etc) that the updated is published.
2222

23-
## Keeping TempestPHP Secure
23+
## Keeping Tempest secure
2424

25-
Several controls are in place to ensure that TempestPHP code releases are kept secure.
25+
Several controls are in place to ensure that Tempest code releases are kept secure.
2626

27-
1. All maintainers with write access to the repository (currently, just core maintainers) utilise Multi-Factor Authentication.
27+
1. All maintainers with write access to the repository use multi-factor authentication.
2828

2929
2. Branch protection is configured on the repository.
3030

3131
3. All access rights and privileges (including automated accounts, API keys) are assigned on a Principle of Least Privilege basis.
3232

33-
4. Every Pull Request requires the successful completion of code quality and static analysis checks, and is reviewed by a core maintainer.
33+
4. Every pull request requires the successful completion of code quality and static analysis checks, and is reviewed by a core maintainer.
3434

35-
5. TempestPHP actively upgrades dependencies based on deprecations and notices from upstream packages where used.
35+
5. Tempest actively upgrades dependencies based on deprecations and notices from upstream packages where used.

0 commit comments

Comments
 (0)