Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
---
name: Bug report
about: Report a problem so it can be reproduced and fixed
labels: bug
---

## Description

<!-- What is wrong. -->

## Steps to reproduce

1.
2.

## Expected vs actual

## Environment

<!-- Version, commit, environment. Do not include secrets or production data. -->
13 changes: 13 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
name: Feature request
about: Propose an improvement or new capability
labels: enhancement
---

## Problem

<!-- What need or gap this addresses. -->

## Proposed solution

## Alternatives considered
15 changes: 15 additions & 0 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
## Summary

<!-- What does this change do, and why. -->

## Related issue

<!-- Link the issue. Use the expected key format in the PR title as well. -->

## Checklist

- [ ] Title follows Conventional Commits and references the issue
- [ ] Required checks pass
- [ ] Tests added or updated where it makes sense
- [ ] No secrets, keys, credentials or `.env` files are included
- [ ] Security impact considered (permissions, dependencies, exposed data)
14 changes: 14 additions & 0 deletions CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# Default code owners for the aziontech organization.
#
# These defaults apply to repositories that do not define their own CODEOWNERS.
# Policy, security and CI baseline files are owned jointly by the Security Office
# and Delivery Engineering: changes to them require review from both.

# Security and governance policy
/SECURITY.md @aziontech/security-office
/CODEOWNERS @aziontech/security-office @aziontech/team-delivery-engineering

# Contribution and workflow baselines
/CONTRIBUTING.md @aziontech/team-delivery-engineering @aziontech/security-office
/.github/ @aziontech/team-delivery-engineering @aziontech/security-office
/workflow-templates/ @aziontech/team-delivery-engineering @aziontech/security-office
31 changes: 31 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# Contributing

These are the default contribution guidelines for the `aziontech` organization.
A repository may define its own `CONTRIBUTING.md`, which takes precedence.

## Pull requests

- Keep pull requests focused and reasonably small.
- Write a clear title and description. Follow Conventional Commits in the title
(for example `feat:`, `fix:`, `chore:`), and reference the related issue.
- Make sure the required checks pass before requesting a merge.
- Request review from the appropriate code owners.

## Commits

- Use clear, imperative commit messages.
- Do not commit generated artifacts, large binaries, secrets or credentials.

## Security and secrets

- Never commit secrets, private keys, credentials or environment files.
- If you believe you committed a secret, treat it as exposed: rotate it and
remove it from history. Removing the line in a later commit is not enough.
- Running a pre-commit hook locally is strongly recommended to catch secrets and
common issues before they leave your machine.

## Quality

- Add or update tests when you change behavior.
- Keep code style consistent with the surrounding code and the repository's
linters.
45 changes: 45 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
# Security Policy

This policy applies by default to repositories in the `aziontech` organization
that do not define their own `SECURITY.md`.

## Reporting a vulnerability

Please report security vulnerabilities responsibly and do not open a public issue
for them.

Preferred channel: use GitHub's private vulnerability reporting on the affected
repository ("Security" tab, "Report a vulnerability"). If that is not available,
contact the Security Office through the organization's designated security contact.

> Maintainers: confirm and pin the security contact channel for this line before
> relying on it.

When reporting, please include, when possible:

- A description of the issue and its potential impact.
- Steps to reproduce, or a minimal proof of concept.
- Affected repository, version, commit or environment.
- Any suggested remediation you may have.

Please do not include real secrets, credentials or production data in a report.
Redact them and describe the class of the exposure instead.

## What to expect

- Acknowledgement of the report as soon as it is triaged.
- An assessment of severity and an initial response with next steps.
- Coordination on a fix and a disclosure timeline proportional to severity.

## Scope

This default policy covers source code and configuration hosted in this
organization. Findings in third party dependencies should be reported upstream
and, when they affect us, also through the channel above.

## Good practices we ask of everyone

- Never commit secrets, private keys, credentials or `.env` files. Use the
approved secret management instead.
- Prefer least privilege for tokens, workflow permissions and access grants.
- Keep dependencies current and address high severity advisories promptly.
7 changes: 7 additions & 0 deletions profile/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Azion

Public profile for the `aziontech` organization.

This repository holds the organization's default community health files: security
policy, contribution guidelines, and issue and pull request templates. Any
repository that does not define its own version inherits the defaults here.