security: public-claims accuracy: SECURITY.md, AUDIT_POSTURE, profile + public-truth gate - #7
Merged
Merged
Conversation
…iled tier table, no private-archive or PGP path Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P
…endpoints only Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P
SaulBuilds
force-pushed
the
fix/pba-r2-truth
branch
from
September 25, 2026 06:23
18f210c to
9e249e8
Compare
…E; public-truth checks every .md for bounty links and tighter qualifiers Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P
…s with or without BOUNTY.md Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pre-bounty remediation R2, public-claims accuracy. This PR fixes the org security policy and the profile claims, and adds a draft bug bounty.
scripts/ci/public_truth.pyci.yml@v1, ws, specs pathgit ls-remote, so it works under a shallow checkout)@v1→ FAILHITL/H.I.T.L, plus a whitespace-normalised "human in the loop")Rework (independent verifier)
teeOracleCount()is 0).Local CI
No open Dependabot PRs.
Pass 2
public_truth.pynow checks every.mdfor BOUNTY.md links while it is not in force, requires qualifiers next to the claim, catches 'generally available' paid rails and numbered or prose Known-issues entries (all probes FAIL; origin/main 18; head OK).Split
BOUNTY.mdmoved to its own draft PR ("draft: bug bounty policy (owner to fill)"). This PR no longer adds it, so it can merge now.public_truth.pypasses with or withoutBOUNTY.md. While the file is absent, any.mdthat links it fails. While it is present, its structure and placeholder rules apply.🤖 Generated with Claude Code
https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P