From 9b558c5fe8528904f56d9da568db0591c0f3f4f5 Mon Sep 17 00:00:00 2001 From: Renan Dias Date: Tue, 29 Sep 2026 17:44:23 -0300 Subject: [PATCH] docs(defaults): add org-wide security, contributing, templates and CODEOWNERS Populate the organization default community health files, which apply to every repo without its own version: - SECURITY.md: responsible disclosure policy and baseline security guidance. - CONTRIBUTING.md: PR, commit, secret hygiene and quality guidelines. - CODEOWNERS: policy and workflow files owned jointly by Security Office and Delivery Engineering. - PR and issue templates. - profile/README.md for the public org profile. Content is intentionally macro and generic. Deep, flow-specific policies (break glass, secrets policy) live in their owning cards and the internal playbook, not in this public repo. Co-Authored-By: Claude Opus 4.8 --- .github/ISSUE_TEMPLATE/bug_report.md | 20 ++++++++++ .github/ISSUE_TEMPLATE/feature_request.md | 13 +++++++ .github/PULL_REQUEST_TEMPLATE.md | 15 ++++++++ CODEOWNERS | 14 +++++++ CONTRIBUTING.md | 31 ++++++++++++++++ SECURITY.md | 45 +++++++++++++++++++++++ profile/README.md | 7 ++++ 7 files changed, 145 insertions(+) create mode 100644 .github/ISSUE_TEMPLATE/bug_report.md create mode 100644 .github/ISSUE_TEMPLATE/feature_request.md create mode 100644 .github/PULL_REQUEST_TEMPLATE.md create mode 100644 CODEOWNERS create mode 100644 CONTRIBUTING.md create mode 100644 SECURITY.md create mode 100644 profile/README.md diff --git a/.github/ISSUE_TEMPLATE/bug_report.md b/.github/ISSUE_TEMPLATE/bug_report.md new file mode 100644 index 0000000..4970f33 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.md @@ -0,0 +1,20 @@ +--- +name: Bug report +about: Report a problem so it can be reproduced and fixed +labels: bug +--- + +## Description + + + +## Steps to reproduce + +1. +2. + +## Expected vs actual + +## Environment + + diff --git a/.github/ISSUE_TEMPLATE/feature_request.md b/.github/ISSUE_TEMPLATE/feature_request.md new file mode 100644 index 0000000..945fab5 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/feature_request.md @@ -0,0 +1,13 @@ +--- +name: Feature request +about: Propose an improvement or new capability +labels: enhancement +--- + +## Problem + + + +## Proposed solution + +## Alternatives considered diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md new file mode 100644 index 0000000..e050b52 --- /dev/null +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -0,0 +1,15 @@ +## Summary + + + +## Related issue + + + +## Checklist + +- [ ] Title follows Conventional Commits and references the issue +- [ ] Required checks pass +- [ ] Tests added or updated where it makes sense +- [ ] No secrets, keys, credentials or `.env` files are included +- [ ] Security impact considered (permissions, dependencies, exposed data) diff --git a/CODEOWNERS b/CODEOWNERS new file mode 100644 index 0000000..ce7fdec --- /dev/null +++ b/CODEOWNERS @@ -0,0 +1,14 @@ +# Default code owners for the aziontech organization. +# +# These defaults apply to repositories that do not define their own CODEOWNERS. +# Policy, security and CI baseline files are owned jointly by the Security Office +# and Delivery Engineering: changes to them require review from both. + +# Security and governance policy +/SECURITY.md @aziontech/security-office +/CODEOWNERS @aziontech/security-office @aziontech/team-delivery-engineering + +# Contribution and workflow baselines +/CONTRIBUTING.md @aziontech/team-delivery-engineering @aziontech/security-office +/.github/ @aziontech/team-delivery-engineering @aziontech/security-office +/workflow-templates/ @aziontech/team-delivery-engineering @aziontech/security-office diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..05aba78 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,31 @@ +# Contributing + +These are the default contribution guidelines for the `aziontech` organization. +A repository may define its own `CONTRIBUTING.md`, which takes precedence. + +## Pull requests + +- Keep pull requests focused and reasonably small. +- Write a clear title and description. Follow Conventional Commits in the title + (for example `feat:`, `fix:`, `chore:`), and reference the related issue. +- Make sure the required checks pass before requesting a merge. +- Request review from the appropriate code owners. + +## Commits + +- Use clear, imperative commit messages. +- Do not commit generated artifacts, large binaries, secrets or credentials. + +## Security and secrets + +- Never commit secrets, private keys, credentials or environment files. +- If you believe you committed a secret, treat it as exposed: rotate it and + remove it from history. Removing the line in a later commit is not enough. +- Running a pre-commit hook locally is strongly recommended to catch secrets and + common issues before they leave your machine. + +## Quality + +- Add or update tests when you change behavior. +- Keep code style consistent with the surrounding code and the repository's + linters. diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..bfb0d6b --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,45 @@ +# Security Policy + +This policy applies by default to repositories in the `aziontech` organization +that do not define their own `SECURITY.md`. + +## Reporting a vulnerability + +Please report security vulnerabilities responsibly and do not open a public issue +for them. + +Preferred channel: use GitHub's private vulnerability reporting on the affected +repository ("Security" tab, "Report a vulnerability"). If that is not available, +contact the Security Office through the organization's designated security contact. + +> Maintainers: confirm and pin the security contact channel for this line before +> relying on it. + +When reporting, please include, when possible: + +- A description of the issue and its potential impact. +- Steps to reproduce, or a minimal proof of concept. +- Affected repository, version, commit or environment. +- Any suggested remediation you may have. + +Please do not include real secrets, credentials or production data in a report. +Redact them and describe the class of the exposure instead. + +## What to expect + +- Acknowledgement of the report as soon as it is triaged. +- An assessment of severity and an initial response with next steps. +- Coordination on a fix and a disclosure timeline proportional to severity. + +## Scope + +This default policy covers source code and configuration hosted in this +organization. Findings in third party dependencies should be reported upstream +and, when they affect us, also through the channel above. + +## Good practices we ask of everyone + +- Never commit secrets, private keys, credentials or `.env` files. Use the + approved secret management instead. +- Prefer least privilege for tokens, workflow permissions and access grants. +- Keep dependencies current and address high severity advisories promptly. diff --git a/profile/README.md b/profile/README.md new file mode 100644 index 0000000..976d403 --- /dev/null +++ b/profile/README.md @@ -0,0 +1,7 @@ +# Azion + +Public profile for the `aziontech` organization. + +This repository holds the organization's default community health files: security +policy, contribution guidelines, and issue and pull request templates. Any +repository that does not define its own version inherits the defaults here.