You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Repository policy can define a private-first vulnerability-disclosure process, but source text and CI cannot prove that GitHub private vulnerability reporting is enabled, visible to external reporters, monitored, staffed, or operational. Until those live administrator and case-handling controls are evidenced, reporters may have only the content-free public-contact fallback.
Current clean policy implementation: PR #95, exact head 1fc38bb3234f1ffca35989c52682ee76fce45b9b on protected base c85d710804139c0697d7ef8fa47d02b1389e6d84.
Fresh current-head evidence:
application ci run 31383398820: terminal success;
reviewer-ci run 31383399170: terminal success;
central Security Scan run 31383398494: terminal success under its scanner/revision semantics;
predecessor CodeRabbit test-contract finding is addressed by a throwing body getter regression and the inline thread is resolved;
no qualifying independent non-author formal APPROVED review is established;
root SECURITY.md with private-first reporting and content-free public fallback;
docs/security/vulnerability-handling.md with case roles/states, exact-source evidence, incident escalation, test-first remediation, independent review, bounded retention, legal-hold and secure-deletion/redaction semantics;
docs/security/private-vulnerability-reporting-audit.md with the live-setting evidence procedure;
a read-only GitHub status probe that permits only organization-scoped GET, uses a 20-second timeout, strict UTF-8 streaming and 16 KiB ceiling, and passes only on explicit boolean enabled: true;
executable policy/audit regressions and standards doctoring.
A passing setting probe is setting evidence only. It does not prove reporter UI visibility, notifications, staffing, case access, independent review, release/deployment acceptance, or acquisition readiness.
Fresh live setting evidence — 2026-08-15
protected main at observation: 86ad5cba7089da125fabc75a42e8b240654bf866;
authenticated repository API GET /repos/ContextualWisdomLab/noema/private-vulnerability-reporting returned the explicit object { "enabled": true };
repository visibility remained public;
the active organization ruleset remained CWL Noema central security scan, with no bypass actors and current_user_can_bypass="never".
This closes only the administrator-setting fact. It does not prove the external reporter UI, notification delivery, staffing/backup coverage, case access, or a benign end-to-end disclosure exercise. The protected-source audit receipt also remains separately required.
Run the read-only private-vulnerability-reporting audit from protected source and retain exact repository/source/timestamp/result evidence.
Live administrator / reporter evidence
A repository administrator enables GitHub private vulnerability reporting for ContextualWisdomLab/noema without weakening repository visibility, branch protection, Actions, review, or advisory controls.
The repository Security interface exposes Report a vulnerability to an unauthenticated or ordinary external reporter as GitHub supports.
The protected-source read-only audit records status: PASS; a failing or unavailable result remains fail closed and may not be edited into PASS.
Staffing / exercise evidence
At least two authorized maintainers or the approved security team receive and can access private reports; ownership and backup coverage are documented without publishing secrets or unnecessary personal data.
A benign end-to-end exercise creates a private report or draft advisory, records UTC timestamps for receipt and acknowledgement, and proves that no vulnerability details enter public issues, pull requests, CI logs, model prompts, or public artifacts.
Notification delivery and backup ownership are observed rather than inferred.
Evidence identifies repository, administrator setting, exercise case identifier, actors/roles, observation time and limitations; screenshots/exports remain access controlled and contain no tokens, private keys, exploit payloads or unnecessary PII.
The exercise verifies duplicate handling, independent technical review assignment, state transitions, and closure/deletion according to the vulnerability-handling lifecycle.
The disabled/unavailable setting path uses only the content-free Private security contact requested fallback and moves technical details into an approved private case before handling.
Buyer / documentation evidence
After live proof exists, reconcile SECURITY.md, vulnerability-handling/runbook, canonical fix(security): bind workflow source and document MSA boundaries #71 documentation/traceability and buyer data-room evidence without promoting settings or staffing that were not observed.
Retained public acquisition evidence proves control operation without exposing reporter identity, vulnerability details, exploit-enabling content or secrets.
Non-goals / guardrails
No public vulnerability details, synthetic enabled-setting claim, invented security contact/PGP/bounty/SLA/compensation/24x7 staffing, branch-repair/self-modifying Action, reviewer/release credential workaround, protection bypass, synthetic approval, or release merely because policy/checks are green.
Buyer-visible gap
Repository policy can define a private-first vulnerability-disclosure process, but source text and CI cannot prove that GitHub private vulnerability reporting is enabled, visible to external reporters, monitored, staffed, or operational. Until those live administrator and case-handling controls are evidenced, reporters may have only the content-free public-contact fallback.
Current clean policy implementation: PR #95, exact head
1fc38bb3234f1ffca35989c52682ee76fce45b9bon protected basec85d710804139c0697d7ef8fa47d02b1389e6d84.Fresh current-head evidence:
cirun31383398820: terminal success;reviewer-cirun31383399170: terminal success;Security Scanrun31383398494: terminal success under its scanner/revision semantics;bodygetter regression and the inline thread is resolved;These source/check results do not prove this issue's live operational controls or merge authority.
Repository-owned evidence boundary
#95 provides, subject to protected integration:
SECURITY.mdwith private-first reporting and content-free public fallback;docs/security/vulnerability-handling.mdwith case roles/states, exact-source evidence, incident escalation, test-first remediation, independent review, bounded retention, legal-hold and secure-deletion/redaction semantics;docs/security/private-vulnerability-reporting-audit.mdwith the live-setting evidence procedure;GET, uses a 20-second timeout, strict UTF-8 streaming and 16 KiB ceiling, and passes only on explicit booleanenabled: true;A passing setting probe is setting evidence only. It does not prove reporter UI visibility, notifications, staffing, case access, independent review, release/deployment acceptance, or acquisition readiness.
Fresh live setting evidence — 2026-08-15
mainat observation:86ad5cba7089da125fabc75a42e8b240654bf866;GET /repos/ContextualWisdomLab/noema/private-vulnerability-reportingreturned the explicit object{ "enabled": true };public;CWL Noema central security scan, with no bypass actors andcurrent_user_can_bypass="never".This closes only the administrator-setting fact. It does not prove the external reporter UI, notification delivery, staffing/backup coverage, case access, or a benign end-to-end disclosure exercise. The protected-source audit receipt also remains separately required.
Acceptance criteria
Protected policy prerequisite
Live administrator / reporter evidence
ContextualWisdomLab/noemawithout weakening repository visibility, branch protection, Actions, review, or advisory controls.status: PASS; a failing or unavailable result remains fail closed and may not be edited into PASS.Staffing / exercise evidence
Private security contact requestedfallback and moves technical details into an approved private case before handling.Buyer / documentation evidence
SECURITY.md, vulnerability-handling/runbook, canonical fix(security): bind workflow source and document MSA boundaries #71 documentation/traceability and buyer data-room evidence without promoting settings or staffing that were not observed.Non-goals / guardrails
No public vulnerability details, synthetic enabled-setting claim, invented security contact/PGP/bounty/SLA/compensation/24x7 staffing, branch-repair/self-modifying Action, reviewer/release credential workaround, protection bypass, synthetic approval, or release merely because policy/checks are green.
Related: #27, #29, #40, #71, #72, #95