Skip to content

docs: link the contributing guide straight at the security policy - #19

Merged
aljo242 merged 2 commits into
mainfrom
docs/link-directly-to-policy
Oct 1, 2026
Merged

aljo242 merged 2 commits into
mainfrom
docs/link-directly-to-policy

Conversation

@aljo242

@aljo242 aljo242 commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

CONTRIBUTING.md linked cosmos/security/SECURITY.md, which points straight back here. Now a relative link.

Leave that pointer file alone, 11 other links still depend on it.

The link pointed at cosmos/security/SECURITY.md, which has been a pointer back
to this file since #15. Contributors were sent to another repository to be sent
back here. The policy lives in this repo, so link it relatively.
@aljo242
aljo242 marked this pull request as ready for review October 1, 2026 14:59
@aljo242
aljo242 requested a review from a team as a code owner October 1, 2026 14:59
@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[Low risk] Updates a documentation link in the contributing guide.

The PR should not merge until the policy link works from repositories that consume the organization-wide guide.

Findings

  1. P1 Policy link may break ▶

Summary

The PR replaces an external security-policy link in the organization-wide contributing guide with a relative link.

  • The new link works in cosmos/.github, but may not work when the guide is displayed by another repository.

Reviews (1) · Last reviewed commit: "docs: link the contributing guide straig..."

Comment thread CONTRIBUTING.md Outdated
Never open a public issue, pull request, or discussion for a suspected
vulnerability. Report it through the
[security policy](https://github.com/cosmos/security/blob/main/SECURITY.md)
[security policy](SECURITY.md)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Policy link may break If a Cosmos repository displays this organization-wide guide but has no SECURITY.md of its own, the relative link can resolve against that repository. Contributors would then reach a missing file instead of the disclosure policy. Link directly to the policy in cosmos/.github so it works from consuming repositories.

This file is an org default community health file, so GitHub serves it from
repositories that have no CONTRIBUTING of their own. A relative SECURITY.md
resolves against the consuming repository, and cosmos/evm, cosmos/cosmos-sdk and
cosmos/ibc-go have no SECURITY.md of their own, so the link would have 404'd for
exactly the repositories this file exists to serve.

Absolute to cosmos/.github still removes the round trip through cosmos/security,
which was the point of the change.
@aljo242
aljo242 merged commit 8e836d4 into main Oct 1, 2026
1 check passed
@aljo242
aljo242 deleted the docs/link-directly-to-policy branch October 1, 2026 17:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants