Skip to content

docs(vulnerability-disclosure): normalize structure and wording - #567

Merged
mattaereal merged 7 commits into
developfrom
docs/normalize-vulnerability-disclosure
Jul 27, 2026
Merged

docs(vulnerability-disclosure): normalize structure and wording#567
mattaereal merged 7 commits into
developfrom
docs/normalize-vulnerability-disclosure

Conversation

@mattaereal

Copy link
Copy Markdown
Collaborator

Scope

Normalize the Vulnerability Disclosure framework (docs/pages/vulnerability-disclosure/) to the content model.

Why

Structure as of develop lacked Key Takeaways, contributors frontmatter, overview page map, Related frameworks, and Further reading. Prose needed light editorial cleanup (clarity only).

Content model applied

  • Framework overview + conceptual pages
  • Canonical Key Takeaway form
  • Shared page chrome (TagList, AttributionList, ContributeFooter)
  • Frontmatter contract
  • Overview page map synced to sidebar children

Changes

  • overview.mdx: KT, basics, page map, related frameworks, further reading, contributors
  • security-contact.mdx: KT, clearer sectioning, further reading, contributors
  • bug-bounties.mdx: KT, platform notes softened as market-time (no new controls), further reading, contributors

Substantive security changes

None. Editorial/structural only. Existing platform names and practices retained; vendor claims labeled as vendor-described where relevant.

Intentionally unchanged

  • Sidebar entries already present (dev: true)
  • Generated index.mdx
  • No Safe Harbor legal text changes (cross-link only)

Validation

  • cspell on touched paths — clean
  • markdownlint-cli2 on touched paths — clean
  • full docs:build (not re-run this PR; structural MDX only)
  • no generated files hand-edited
  • commit signed

Dependencies

Depends on content standards in #561 (unmerged). Apply #561 rules by reference; this PR does not copy standards files.

Reviewer focus

  • Disclosure/Safe Harbor vs bounty boundary wording stays accurate
  • External links (ISO overview, FIRST, security.txt, GitHub docs) acceptable
  • No invented legal or bounty-policy requirements

Add Key Takeaways, contributors, page map, related frameworks, and
Further reading. Editorial cleanup only; no new security controls.
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 26, 2026

Copy link
Copy Markdown

Deploying frameworks with  Cloudflare Pages  Cloudflare Pages

Latest commit: 55942b1
Status:⚡️  Build in progress...

View logs

Match develop authorship exactly. Clear wrote/reviewed/fact-checked
arrays where normalization invented authors on pages that had none.
Do not attribute chrome-only edits as content authorship.
Rewrite non-stub frontmatter descriptions into the acceptable length
band (preferred 140–160). Stub pages exempt. No body or credit changes.
Rename Further Reading H2s to the exact title the updated #561 validator accepts; sentence-case a few common section headings.
…uation

Replace an awkward triage bullet on the overview and terminate the bug
bounties description with a period for consistent frontmatter style.

@frameworks-volunteer frameworks-volunteer left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Model: z-ai/glm-5.2 Reasoning: medium Provider: openrouter

Approve. Clean editorial/structural normalization of the vulnerability-disclosure framework.

Security: no concerns. Docs-only changes, no secrets, no injection vectors, no unsafe patterns. Vendor claims (Hackenproof E2E encryption) correctly hedged with "as described by the vendor."

QA:

  • cspell clean, markdownlint clean on all 3 touched files
  • All internal links resolve to existing pages (safe-harbor, external-security-reviews, incident-management, secure-software-development, security-testing, security-contact, bug-bounties)
  • External links relevant and valid (ISO 29147, FIRST PSIRT, security.txt, RFC 9116, GitHub docs, vendor sites, disclose.io)
  • Frontmatter matches convention from encryption normalization (empty contributor arrays, 140-160 char descriptions)
  • Key Takeaways all under 40 words, canonical form with 🔑 emoji
  • No leftover debug content, TODOs, or placeholder text
  • Commit "docs: drop invented contributor credits" correctly removed any spurious attributions

No blocking issues. Ready to merge.

Comment thread docs/pages/vulnerability-disclosure/overview.mdx Outdated
Comment thread docs/pages/vulnerability-disclosure/security-contact.mdx Outdated
@mattaereal
mattaereal merged commit 3811636 into develop Jul 27, 2026
5 of 6 checks passed
@frameworks-volunteer

Copy link
Copy Markdown
Collaborator

Model: moonshotai/kimi-k2.6 Reasoning: medium Provider: openrouter

Re-checked the two commits pushed after the prior approval (ee9ef3a, 55942b1).

Changes since last review — both are heading casing fixes only:

  • overview.mdx: "Further Reading" → "Further reading"
  • security-contact.mdx: "Further Reading" → "Further reading"

No substantive changes. Headings now match the sentence-casing convention referenced in commit e1fdb12. Prior approval stands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants