Skip to content

[2-week comment period thru 26/08/07] 1.0 CONTRIBUTING.md changes: PR/Issue Scope, SECURITY.md, Licensing - #1757

Open
DanGould wants to merge 3 commits into
payjoin:masterfrom
DanGould:contributing-scope-security
Open

[2-week comment period thru 26/08/07] 1.0 CONTRIBUTING.md changes: PR/Issue Scope, SECURITY.md, Licensing#1757
DanGould wants to merge 3 commits into
payjoin:masterfrom
DanGould:contributing-scope-security

Conversation

@DanGould

Copy link
Copy Markdown
Member

As we prepare for rust-payjoin 1.0 maturity and release, I'd like to make some operational policy explicit in CONTRIBUTING.md. Opening the change a 2-week community comment period.

  • Include private responsible disclosure path @ security.md
  • propose CODEOWNERS (maintainers) who can merge (with an ACK), separate from trusted-contributors who have write permission and can green-check ACK maintainers' prs
  • Make licensing terms more explicit

I commit to responding to any substantial comments during the comment period.

Pull Request Checklist

Please confirm the following before requesting review:

DanGould added 3 commits July 21, 2026 14:23
GitHub surfaces this file in the Security tab and in the report-a-
vulnerability flow, so private disclosure has a discoverable path
instead of landing in the public issue tracker.
GitHub requests review from listed owners on every PR, and the file
makes the maintainer set public and machine-readable. Enforcement via
the require-review-from-code-owners branch protection setting is a
separate decision.
Write down the norms a contributor needs while working in this
repository.
@coveralls

Copy link
Copy Markdown
Collaborator

Coverage Report for CI Build 29996669924

Coverage remained the same at 86.374%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 16124
Covered Lines: 13927
Line Coverage: 86.37%
Coverage Strength: 341.84 hits per line

💛 - Coveralls

@xstoicunicornx

Copy link
Copy Markdown
Collaborator

Maybe worth taking this out of draft status? Draft PRs don't necessarily get looked at (I know that I tend to skip them).

@DanGould
DanGould marked this pull request as ready for review July 29, 2026 17:35

@caarloshenriq caarloshenriq left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Concept ACK

One suggestion on SECURITY.md: it currently lists only an email address for vulnerability reports. Since reports travel through several SMTP hops before reaching a maintainer, projects handling financial software often pair the contact email with a PGP public key or a link to one on a so reporters can encrypt sensitive details in transit.
Worth considering adding a fingerprint or key link alongside the email.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants