Skip to content

DOC Add security release review process#2216

Open
hannahwestra25 wants to merge 5 commits into
microsoft:mainfrom
hannahwestra25:hannahwestra25-document-security-release-reviews
Open

DOC Add security release review process#2216
hannahwestra25 wants to merge 5 commits into
microsoft:mainfrom
hannahwestra25:hannahwestra25-document-security-release-reviews

Conversation

@hannahwestra25

@hannahwestra25 hannahwestra25 commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Description

Adds the customer-facing security links and release governance needed to address the documented partial-compliance gaps:

  • links the public security policy from the README, documentation navigation, and CoPyRIT sidebar
  • adds a public documentation page covering private vulnerability reporting and release security notices
  • requires the release owner to review customer-facing release materials and record evidence in a release work item
  • requires a different PyRIT maintainer to review and approve the final materials before publishing
  • defines required security and compatibility content for every release's notes, including explicit "none known" statements
  • keeps details about security vulnerabilities that have not yet been publicly disclosed in the existing private reporting process

Tests and Documentation

  • npm test -- --runInBand src/components/Sidebar/Navigation.test.tsx
  • npm run type-check
  • npx eslint src/components/Sidebar/Navigation.tsx src/components/Sidebar/Navigation.test.tsx --max-warnings 0
  • jupyter-book build --html

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 485d2633-734b-4ee0-a849-f9adeaf3a9bd
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 485d2633-734b-4ee0-a849-f9adeaf3a9bd
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 485d2633-734b-4ee0-a849-f9adeaf3a9bd
@hannahwestra25
hannahwestra25 marked this pull request as ready for review July 16, 2026 21:18
@hannahwestra25 hannahwestra25 changed the title [DRAFT] DOC Add security release review process DOC Add security release review process Jul 16, 2026

@romanlutz romanlutz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we start with this post-v1?

Comment thread doc/contributing/10_release_process.md Outdated

### Required Release Reviews

Use the existing release work item to record:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

what is the existing release work item?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking a ADO work item, updated wording to reflect that and am thinking of making a template that includes information like

Release x.y.z

Release details

  • Release owner:
  • Target release date:
  • Draft GitHub release notes:
  • Changed public documentation:
  • Changed CoPyRIT UI content or N/A:

Comment thread doc/contributing/10_release_process.md Outdated
Comment thread doc/contributing/10_release_process.md Outdated
Comment thread doc/contributing/10_release_process.md Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 485d2633-734b-4ee0-a849-f9adeaf3a9bd
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 485d2633-734b-4ee0-a849-f9adeaf3a9bd
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants