Skip to content

Document security/report-policy.json for operators #82

@AlphaSudo

Description

@AlphaSudo

Summary

security/report-policy.json controls PR comments (prComment) and nightly rollup issues (nightlyIssue), but there is no dedicated operator doc—only the JSON and workflow references.

Scope (good first issue)

  • Add docs/REPORT_POLICY.md (or a clearly named equivalent) that explains:
    • prComment: enabled, mode (always / actionable / new_findings), header
    • nightlyIssue: enabled, mode, rollupTitle, rollupLabel, labels
    • Where workflows read this file (dast-pr.yml, dast-nightly.yml)
  • Cross-link from docs/QUICK_START.md or README Documentation table.

Acceptance criteria

  • New doc is accurate vs current JSON schema and workflows.
  • At least one existing doc links to it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationgood first issueGood for newcomershelp wantedExtra attention is needed

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions