Scope
Operationally verify that the published security contact is monitored as a PSIRT intake channel and that maintainers can request CVE IDs through the documented MITRE/GitHub CNA path. Verify the published GPG key remains usable for encrypted disclosures.
Discovery context
Issue #753 requires a documented PSIRT/CVE process and support policy. During Architect/Critic review, the repository evidence confirmed that inquiry@cleverplant.com is published, but did not prove live mailbox ownership/monitoring, a designated CVE assignee, or an end-to-end encrypted-report exercise. These are operational facts that should not be invented in documentation.
Acceptance criteria
- Maintainer confirms the mailbox receives a test security report and records the on-call/triage owner privately.
- Maintainer records the authorized CVE assignment path and completes a test request or documents the CNA/MITRE response.
- The published GPG fingerprint encrypts and decrypts a test message successfully.
- Update
SECURITY.md or the release runbook with only the verified operational details.
Priority and dependency
Security/release blocker follow-up. Depends on the public policy documentation in #753, but requires maintainer or service-owner access that is not available from repository code alone.
Scope
Operationally verify that the published security contact is monitored as a PSIRT intake channel and that maintainers can request CVE IDs through the documented MITRE/GitHub CNA path. Verify the published GPG key remains usable for encrypted disclosures.
Discovery context
Issue #753 requires a documented PSIRT/CVE process and support policy. During Architect/Critic review, the repository evidence confirmed that
inquiry@cleverplant.comis published, but did not prove live mailbox ownership/monitoring, a designated CVE assignee, or an end-to-end encrypted-report exercise. These are operational facts that should not be invented in documentation.Acceptance criteria
SECURITY.mdor the release runbook with only the verified operational details.Priority and dependency
Security/release blocker follow-up. Depends on the public policy documentation in #753, but requires maintainer or service-owner access that is not available from repository code alone.