Skip to content

Created Security Policy#4096

Merged
balegas merged 2 commits intomainfrom
balegas-patch-1
Apr 7, 2026
Merged

Created Security Policy#4096
balegas merged 2 commits intomainfrom
balegas-patch-1

Conversation

@balegas
Copy link
Copy Markdown
Contributor

@balegas balegas commented Apr 6, 2026

Initial Security.md file

Initial Security.md file
@codecov
Copy link
Copy Markdown

codecov bot commented Apr 6, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 88.67%. Comparing base (649d21c) to head (fd9c17d).
⚠️ Report is 3 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #4096   +/-   ##
=======================================
  Coverage   88.67%   88.67%           
=======================================
  Files          25       25           
  Lines        2438     2438           
  Branches      610      615    +5     
=======================================
  Hits         2162     2162           
  Misses        274      274           
  Partials        2        2           
Flag Coverage Δ
packages/experimental 87.73% <ø> (ø)
packages/react-hooks 86.48% <ø> (ø)
packages/start 82.83% <ø> (ø)
packages/typescript-client 93.81% <ø> (ø)
packages/y-electric 56.05% <ø> (ø)
typescript 88.67% <ø> (ø)
unit-tests 88.67% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

thruflo
thruflo previously requested changes Apr 6, 2026
- The affected version(s) or commit(s)
- Any suggested fix, if you have one

### Response timeline
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These timings seem very slow in reality. We maybe want to say we will strive to reply etc as soon as possible.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

adjust in the spirit of as fast as possible


### Disclosure policy

We follow a **coordinated disclosure** process with a **30-day embargo**:
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are these timings a bit enterprise? We're faster than this.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

no big reasons to change the upper limit. I'll adjust times on the previous section


## Scope

The following are **in scope**:
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Durable Streams?
Phoenix Sync?
TanStack DB?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DS and Ts DB have their own packages, they should have their own security policy

Updated response timeline for security reports to improve acknowledgment and assessment times, and clarified resolution commitments.
@balegas balegas requested a review from thruflo April 6, 2026 23:43
Copy link
Copy Markdown
Contributor

@samwillis samwillis left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@balegas balegas dismissed thruflo’s stale review April 7, 2026 10:44

I believe I've addressed your feedback. I'm merging this to not get blocked. Respond to this PR if you want further changes

@balegas balegas merged commit 441aedf into main Apr 7, 2026
44 checks passed
@balegas balegas deleted the balegas-patch-1 branch April 7, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants