Problem Statement
New contributors currently need to understand the project architecture and safety requirements before making changes.
Security reporting also needs a clear process.
Proposed Solution / Enhancement
Add:
CONTRIBUTING.md
SECURITY.md
CONTRIBUTING.md should explain:
- Project architecture
- Development setup
- Running tests
- Writing tests
- Pull request expectations
- Coding conventions
SECURITY.md should explain:
- How to report security issues
- What information should be included
- What should not be publicly disclosed
Architectural Layer Impacted
Documentation / Open Source / Security
Alternatives Considered
Leaving contributor and security guidance undocumented increases onboarding time and can result in unsafe public disclosure of vulnerabilities.
Problem Statement
New contributors currently need to understand the project architecture and safety requirements before making changes.
Security reporting also needs a clear process.
Proposed Solution / Enhancement
Add:
CONTRIBUTING.mdSECURITY.mdCONTRIBUTING.mdshould explain:SECURITY.mdshould explain:Architectural Layer Impacted
Documentation / Open Source / Security
Alternatives Considered
Leaving contributor and security guidance undocumented increases onboarding time and can result in unsafe public disclosure of vulnerabilities.