From bdb0a02c220f003a4784c3e705770805ed2aa986 Mon Sep 17 00:00:00 2001 From: Renaud Calle Date: Tue, 29 Sep 2026 14:56:25 +0000 Subject: [PATCH 1/2] =?UTF-8?q?=F0=9F=93=9D=20docs:=20add=20AI=20usage=20a?= =?UTF-8?q?nd=20security=20policies?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- AI_POLICY.md | 71 ++++++++++++++++++++++++++++++++++++++++++++++++++++ SECURITY.md | 45 +++++++++++++++++++++++++++++++++ 2 files changed, 116 insertions(+) create mode 100644 AI_POLICY.md create mode 100644 SECURITY.md diff --git a/AI_POLICY.md b/AI_POLICY.md new file mode 100644 index 0000000..6ef1aa6 --- /dev/null +++ b/AI_POLICY.md @@ -0,0 +1,71 @@ +# AI Usage Policy + +AI-assisted contributions are allowed. + +Unreviewed AI-generated contributions **are not**. + +## Rule + +If you submit an issue, pull request, comment, review, documentation change, or code contribution, you are responsible for its content. + +Before submitting AI-assisted content, you must: + +* read it; +* understand it; +* verify it; +* test it when applicable; +* make sure it actually reflects what you want to contribute. + +Do not submit raw AI output and expect maintainers to review it for you. + +## Pull Requests + +If AI helped generate code, you are still expected to understand the resulting changes. + +You should be able to explain: + +* what the code does; +* why the change is necessary; +* why the chosen implementation makes sense; +* what you tested. + +If you cannot explain your own pull request without asking an AI tool, it is not ready to be submitted. + +## Issues and Discussions + +AI may help you structure or improve an issue, but the final content must describe a real problem you understand. + +Do not submit speculative AI-generated bug reports, root-cause analyses, feature requests, or large explanations that you have not verified yourself. + +A short and accurate issue is more useful than a long generated one. + +## Reviews and Comments + +Do not blindly paste maintainer feedback into an AI tool and paste the response back. + +AI can help you investigate or formulate an answer, but you are expected to read, understand, and agree with anything you post. + +## Responsibility + +AI is a "tool", not a contributor. + +Do not blame it for incorrect code, bad documentation, invented APIs, security issues, or misleading information. + +If you submit it, **you own it**. + +## Maintainer Discretion + +Maintainers may close or reject contributions that appear to be: + +* blindly AI-generated; +* unreviewed; +* unnecessarily verbose; +* unrelated to the reported problem; +* technically incorrect; +* submitted by someone who does not understand the contribution. + +The goal of this policy is not to discourage the use of AI. + +The goal is simple: + +> **Use AI to help you do the work. Do not make maintainers review AI output that you have not reviewed yourself.** diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..15edc2b --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,45 @@ +# Security Policy + +## Reporting a Vulnerability + +If you believe you have discovered a security vulnerability in this project, please **do not open a public GitHub issue**. + +Whenever possible, use GitHub's **Private Vulnerability Reporting** feature: + +1. Go to the **Security and quality** tab of the repository. +2. Select **Report a vulnerability**. +3. Provide as much information as possible about the issue. + +This is the preferred way to report security vulnerabilities. + +## Alternative Contact + +If **Report a vulnerability** is not available for this repository, you can contact us through one of the following channels: + +* **Discord:** [https://discord.gg/HUVtY5gT6s] +* **Email:** [opensource@outscale.com] + +Please do not post vulnerability details publicly on Discord. Contact us first so that we can continue the discussion privately. + +## What to Include + +When reporting a vulnerability, please include as much relevant information as possible, such as: + +* A description of the vulnerability +* The affected component or version +* Steps to reproduce the issue +* The potential impact +* Any proof of concept, logs, or screenshots that may help us understand the issue +* A suggested fix or mitigation, if you have one + +## Responsible Disclosure + +We ask that you give us a reasonable amount of time to investigate and address the vulnerability before publicly disclosing it. + +We appreciate security researchers and community members who take the time to responsibly report potential security issues. + +## Security-related GitHub Issues + +Public GitHub issues should **not** be used to report vulnerabilities. + +If a security-related issue is opened publicly, we may close or remove it and ask the reporter to use the private vulnerability reporting process instead. \ No newline at end of file From a81cd82a173f4a5f211fc58b7d193c23daf2a10e Mon Sep 17 00:00:00 2001 From: Renaud Calle Date: Tue, 29 Sep 2026 14:56:44 +0000 Subject: [PATCH 2/2] =?UTF-8?q?=F0=9F=91=B7=20ci:=20add=20Gitleaks=20workf?= =?UTF-8?q?low=20for=20security=20scanning?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/gitleaks.yml | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 .github/workflows/gitleaks.yml diff --git a/.github/workflows/gitleaks.yml b/.github/workflows/gitleaks.yml new file mode 100644 index 0000000..9ba650c --- /dev/null +++ b/.github/workflows/gitleaks.yml @@ -0,0 +1,24 @@ +name: Gitleaks + +on: + push: + branches: [main] + pull_request: + workflow_dispatch: + +permissions: + contents: read + pull-requests: read + +jobs: + gitleaks: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + fetch-depth: 0 + persist-credentials: false + + - uses: outscale/.github/gitleaks@2d75eac744aeab89dc784a17c9c99e9881c6e30d # v1.2.0 + with: + gitleaks-license: ${{ secrets.GITLEAKS_LICENSE }}