Skip to content

Update SECURITY.md to include instructions on joining the Maintainers Group on the Forum - #38127

Closed
kcowger wants to merge 1 commit into
masterfrom
kcowger-patch-2
Closed

Update SECURITY.md to include instructions on joining the Maintainers Group on the Forum#38127
kcowger wants to merge 1 commit into
masterfrom
kcowger-patch-2

Conversation

@kcowger

@kcowger kcowger commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Product Description

Adds a paragraph to SECURITY.md explaining to self hosters how they can subscribe to early security notifications.

Technical Summary

N/A

Feature Flag

N/A

Safety Assurance

Safety story

N/A

Automated test coverage

N/A

QA Plan

N/A

Rollback instructions

  • This PR can be reverted after deploy with no further considerations

Labels & Review

  • Risk label is set correctly
  • The set of people pinged as reviewers is appropriate for the level of risk of the change

@kcowger
kcowger requested a review from dannyroberts September 8, 2026 21:45
@kcowger kcowger added the product/invisible Change has no end-user visible impact label Sep 8, 2026
Comment thread SECURITY.md
If you host CommCare HQ yourself, request to join the
[Maintainers group](https://forum.dimagi.com/g/maintainers) on the CommCare
forum. Members are automatically subscribed to a private category where we
post when a security update is available, ahead of the full advisory.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pending on Gillian's comment in the doc as well, but I'd say

Suggested change
post when a security update is available, ahead of the full advisory.
post when a security update is available.

@kcowger kcowger closed this Sep 10, 2026
@kcowger
kcowger deleted the kcowger-patch-2 branch September 10, 2026 19:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

product/invisible Change has no end-user visible impact

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants