Skip to content

docs: publish vulnerability remediation targets - #277

Merged
Kevin (kevcube) merged 1 commit into
mainfrom
docs/security-remediation-targets
Sep 2, 2026
Merged

docs: publish vulnerability remediation targets#277
Kevin (kevcube) merged 1 commit into
mainfrom
docs/security-remediation-targets

Conversation

@osterman

Copy link
Copy Markdown
Member

what

  • Adds a Remediation Targets section to the organization security policy: Critical 7 days (72 hours where reachable with an upstream fix available), High 30 days, Medium 90 days, Low next regular release.
  • Targets are measured from confirmation rather than from the report date.
  • Scoped with the sentence "These targets apply to Cloud Posse's actively maintained software products, including the Atmos CLI."

why

  • These targets were approved internally but have never been published, so an assessor reading https://github.com/cloudposse/atmos/security/policy sees a disclosure process with no remediation commitment. A published SLA is expected evidence in supply-chain assessments and for Iron Bank.
  • This file is the organization-level default, inherited by every Cloud Posse repository. A repository-local SECURITY.md would override the whole file for that repo, which means maintaining two nearly identical copies — so the targets go here instead, with an explicit scoping sentence so they do not read as a commitment across dormant module repositories.

Reviewers: the scoping sentence is the part worth arguing about. "Actively maintained software products" is deliberately narrower than "every repository in this organization." If we would rather commit organization-wide, drop that qualifier.

references

  • Raised during the Atmos supply-chain security assessment.
  • Related: cloudposse/atmos PR adding docs/SSDLC.md, whose Section 8 cites these same targets.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Uaxw8BszrDDBNmyFTcDrTx

Adds severity-based remediation targets to the organization security
policy, scoped to actively maintained products. Requested during the
Atmos supply-chain security assessment, where a published SLA is
expected evidence.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Uaxw8BszrDDBNmyFTcDrTx

@kevcube Kevin (kevcube) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@kevcube
Kevin (kevcube) merged commit da6de32 into main Sep 2, 2026
3 checks passed
@kevcube
Kevin (kevcube) deleted the docs/security-remediation-targets branch September 2, 2026 13:48
@kevcube Kevin (kevcube) added documentation Improvements or additions to documentation no-release Do not create a new release (wait for additional code changes) and removed triage Needs triage labels Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation no-release Do not create a new release (wait for additional code changes)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants