Skip to content

Add SECURITY.md and .github/INCIDENT_RESPONSE.md#4032

Merged
filiphr merged 1 commit intomapstruct:mainfrom
filiphr:security-and-irp
Apr 12, 2026
Merged

Add SECURITY.md and .github/INCIDENT_RESPONSE.md#4032
filiphr merged 1 commit intomapstruct:mainfrom
filiphr:security-and-irp

Conversation

@filiphr
Copy link
Copy Markdown
Member

@filiphr filiphr commented Apr 11, 2026

  • SECURITY.md: documents the vulnerability reporting process, supported versions, scope, reporter expectations (including 48-hour acknowledgement and explicit response for out-of-scope reports), and a link to the IRP
  • .github/INCIDENT_RESPONSE.md: internal playbook covering security CVEs, critical regressions, supply-chain incidents, and CI incidents, with severity levels, a yanked-release procedure, secrets rotation index, and a communication channels map

- SECURITY.md: documents the vulnerability reporting process, supported
  versions, scope, reporter expectations (including 48-hour acknowledgement
  and explicit response for out-of-scope reports), and a link to the IRP
- .github/INCIDENT_RESPONSE.md: internal playbook covering security CVEs,
  critical regressions, supply-chain incidents, and CI incidents, with
  severity levels, a yanked-release procedure, secrets rotation index,
  and a communication channels map
@filiphr filiphr added this to the 1.7.0.Beta2 milestone Apr 12, 2026
@filiphr filiphr merged commit fc19409 into mapstruct:main Apr 12, 2026
8 checks passed
@filiphr filiphr deleted the security-and-irp branch April 12, 2026 11:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant