From f5c9790ef1f13dd07f07506e88062d3bb406406b Mon Sep 17 00:00:00 2001 From: Nils Lehnen <30603423+iderex@users.noreply.github.com> Date: Thu, 27 Aug 2026 04:14:22 +0200 Subject: [PATCH] Point the shut reporting route at the file that holds its state [#206] SECURITY.md named the private reporting form as the destination, said in the same breath that the form does not answer, and then sent the reader to issue #57 for the moment it opens. #57 closed as completed on the alternative its own done-when offered, the parity row, rather than on the setting, so the form is still off and a reporter following the pointer met a finished piece of work and nothing telling them the door is shut. That reads as the door having been opened, which is the opposite of the two sentences around the pointer. The paragraph now names the setting rather than an issue and points at docs/parity.md, which carries that setting with the reason and is a tracked file rather than a tracker row that can close underneath it. What the file admits is unchanged: the form does not answer today, and the public issue with as little detail as the report can carry is still written down as the poor arrangement it is. The reading pasted above the paragraph was re-run at this commit and the date moved with it. Found while reading #62, whose last clause waits on the same setting and whose own done-when does not reach this file. Signed-off-by: Nils Lehnen <30603423+iderex@users.noreply.github.com> --- SECURITY.md | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 18e18d6..4396319 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -14,12 +14,14 @@ today: gh api repos/Flowfin/site/private-vulnerability-reporting {"enabled":false} -Run 2026-08-10. So this file names the destination and states plainly that the +Run 2026-08-27. So this file names the destination and states plainly that the destination is currently shut, rather than sending a reporter to a door that -does not open. Opening it is issue #57, and it is not a change to this tree. The -address above is the one the form uses once the setting is on, so nothing here -moves when it changes. Until then the honest alternative is a public issue with -as little detail as the report can carry, which is a poor arrangement and is +does not open. Opening it is a repository setting rather than a change to this +tree, and [docs/parity.md](docs/parity.md) is where that setting is held, beside +the others this repository is measured against and does not have. The address +above is the one the form uses once the setting is on, so nothing here moves +when it changes. Until then the honest alternative is a public issue with as +little detail as the report can carry, which is a poor arrangement and is written down as one. ## What this repository is, and what a problem in it can be