Skip to content

docs(security): align disclosure policy with TRACE v0.2 - #160

Merged
imran-siddique merged 1 commit into
mainfrom
agent/update-security-policy
Aug 11, 2026
Merged

imran-siddique merged 1 commit into
mainfrom
agent/update-security-policy

Conversation

@imran-siddique

Copy link
Copy Markdown
Member

Why

SECURITY.md still described this as only a specification/schema repository and listed v0.1 as the current supported version. The public release includes a Python reference library and v0.2-only verification behavior, so reporters need an accurate scope and support statement.

What changed

  • put signing and verification APIs, schemas, adapters, examples, packaging, and release automation explicitly in scope
  • classify verification bypasses as high-severity implementation findings
  • list TRACE v0.2 and agentrust-trace 0.x as supported
  • mark TRACE v0.1 and earlier drafts unsupported
  • retain GitHub private security advisories as the reporting channel
  • add four policy invariants to prevent the release-facing statements from drifting silently

Verification

  • focused policy tests: 4 passed
  • full suite: 327 passed, 1 skipped
  • ruff check src tests
  • mypy src/agentrust_trace
  • git diff --check

@imran-siddique
imran-siddique marked this pull request as ready for review August 11, 2026 13:00
@imran-siddique
imran-siddique merged commit 0bca118 into main Aug 11, 2026
6 checks passed
@imran-siddique
imran-siddique deleted the agent/update-security-policy branch August 11, 2026 13:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant