Skip to content

docs: add security policy#2127

Open
iamdadmin wants to merge 3 commits intotempestphp:3.xfrom
iamdadmin:3.x-security-policy
Open

docs: add security policy#2127
iamdadmin wants to merge 3 commits intotempestphp:3.xfrom
iamdadmin:3.x-security-policy

Conversation

@iamdadmin
Copy link
Copy Markdown
Contributor

I offered to type this up in the Discord a while ago, Aidan said to go ahead, so now committing this for review.

It's just a light touch and from what I can see outwardly just covers off what you're already doing.

I drew guidance from the following:

If you'd like me to go into more detail or add anything else, I'm happy to work on it.

You may also need to manually link it in the "Security and quality" tab if it's not automatically detected.

In the initial commit I did suggest a security shared email address, but as GH has a private submission form which goes to core maintainers, I just updated to use that link.

Copy link
Copy Markdown
Member

@innocenzi innocenzi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only a syntax review, I haven't checked the policy itself, will need @aidan-casey, @xHeaven and @brendt's review

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
@innocenzi innocenzi changed the title docs: add security.md docs: add security policy Apr 27, 2026
@iamdadmin
Copy link
Copy Markdown
Contributor Author

iamdadmin commented Apr 27, 2026

Only a syntax review, I haven't checked the policy itself

Obviously I can make all of those changes, but from a grammar standpoint;

  • Security Policy is a proper noun, it's a type of policy,
  • Security Issue is a proper noun, it is a type of issue,
  • Pull Request equally is a proper noun, it has a well-known GitHub definition
  • Multi-Factor Authentication is a proper noun, it refers to a specific technology which has a well-known definition,
  • Technically speaking Resolution Process is a proper noun as it is a type of process, but as I'm effectively defining it within the document, instead of it being a pre-existing definition, it could go either way.

So in this context, most of those should in fact be capitalised where used.

If you need the headings to follow the convention so only the first character is a capital, I can re-work it so it doesn't use the proper nouns, but the references within the paragraphs themselves should remain capitalised. Would that work? (And I can obviously do a commit changing TempestPHP to Tempest...)

@innocenzi
Copy link
Copy Markdown
Member

innocenzi commented Apr 27, 2026

Sorry, but you're incorrect. None of those are "proper nouns", they're actually common nouns, even those referring to very specific concepts.

Let's stick to sentence case to stay consistent with the current documentation and keep it easy to scan

Co-authored-by: Enzo Innocenzi <enzo@innocenzi.dev>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants