mirror of
https://github.com/WeblateOrg/weblate.git
synced 2026-07-26 14:23:58 +08:00
This just better documents existing practices and consolidates documentation in a shape that it is easier to find.
45 lines
1.9 KiB
ReStructuredText
Vendored
45 lines
1.9 KiB
ReStructuredText
Vendored
Security governance and assessment status
|
|
=========================================
|
|
|
|
This page summarizes where Weblate publishes security governance information
|
|
and records the current formal assessment status. It is a factual
|
|
documentation index and does not claim certification, audit completion, or
|
|
regulatory compliance.
|
|
|
|
For product identity, contact, support, release, and SBOM identity, see
|
|
:doc:`product-information`.
|
|
|
|
Governance documentation
|
|
------------------------
|
|
|
|
Weblate publishes security governance information in these documentation
|
|
areas:
|
|
|
|
* Contribution rules, code review expectations, and project participation are
|
|
documented in :doc:`/contributing/index`, :doc:`/contributing/code`, and
|
|
:doc:`/contributing/code_of_conduct`.
|
|
* Release lifecycle, security update coverage, and upgrade support are
|
|
documented in :doc:`releases`.
|
|
* Vulnerability reporting, disclosure handling, and service incident reporting
|
|
are documented in :doc:`issues`.
|
|
* Dependency inventory, vulnerability triage, update automation, and container
|
|
scanning are documented in :doc:`dependencies`.
|
|
* Security assumptions and boundaries are documented in :doc:`threat-model`.
|
|
* Release artifact inventory, SBOMs, signatures, attestations, and verification
|
|
are documented in :doc:`release-artifacts`.
|
|
|
|
Formal assessment status
|
|
------------------------
|
|
|
|
This repository does not currently record a formal third-party security
|
|
assessment, certification, audit report, penetration-test report, or formal
|
|
self-assessment for Weblate.
|
|
|
|
Automated security checks and compliance tools such as CodeQL, GitHub
|
|
dependency review, FOSSA, OpenSSF Scorecard, and container vulnerability scans
|
|
are security evidence and automation signals. They are not formal assessments,
|
|
certifications, or audit reports.
|
|
|
|
If Weblate publishes formal assessment evidence in the future, this page and
|
|
the repository security metadata should be updated with the assessment
|
|
reference and date.
|