weblate/docs/security/governance.rst
Michal Čihař 1f52dd7e66 docs: clarify release policy, lifecycle and security support
This just better documents existing practices and consolidates
documentation in a shape that it is easier to find.
2026-06-16 11:06:51 +02:00

45 lines
1.9 KiB
ReStructuredText
Vendored

Security governance and assessment status
=========================================
This page summarizes where Weblate publishes security governance information
and records the current formal assessment status. It is a factual
documentation index and does not claim certification, audit completion, or
regulatory compliance.
For product identity, contact, support, release, and SBOM identity, see
:doc:`product-information`.
Governance documentation
------------------------
Weblate publishes security governance information in these documentation
areas:
* Contribution rules, code review expectations, and project participation are
documented in :doc:`/contributing/index`, :doc:`/contributing/code`, and
:doc:`/contributing/code_of_conduct`.
* Release lifecycle, security update coverage, and upgrade support are
documented in :doc:`releases`.
* Vulnerability reporting, disclosure handling, and service incident reporting
are documented in :doc:`issues`.
* Dependency inventory, vulnerability triage, update automation, and container
scanning are documented in :doc:`dependencies`.
* Security assumptions and boundaries are documented in :doc:`threat-model`.
* Release artifact inventory, SBOMs, signatures, attestations, and verification
are documented in :doc:`release-artifacts`.
Formal assessment status
------------------------
This repository does not currently record a formal third-party security
assessment, certification, audit report, penetration-test report, or formal
self-assessment for Weblate.
Automated security checks and compliance tools such as CodeQL, GitHub
dependency review, FOSSA, OpenSSF Scorecard, and container vulnerability scans
are security evidence and automation signals. They are not formal assessments,
certifications, or audit reports.
If Weblate publishes formal assessment evidence in the future, this page and
the repository security metadata should be updated with the assessment
reference and date.