Skip to content

docs: serve security.txt and point the support page to the bug bounty - #13315

Merged
mergify[bot] merged 1 commit into
mainfrom
devs/JulianMaurin/MRGFY-10192/serve-security-txt-point-support-page-bug-bounty--87f609e7
Oct 8, 2026
Merged

mergify[bot] merged 1 commit into
mainfrom
devs/JulianMaurin/MRGFY-10192/serve-security-txt-point-support-page-bug-bounty--87f609e7

Conversation

@JulianMaurin

Copy link
Copy Markdown
Contributor

docs.mergify.com now serves an RFC 9116 /.well-known/security.txt
whose only contact is the HackerOne program, with Policy pointing to
the security page's "Vulnerability Disclosure" section. The path is
excluded in _routes.json so it is served as a static text/plain file
without going through the Pages middleware.

The support page gains a "Report a Security Vulnerability" section that
sends researchers to HackerOne instead of the support queue.

The Expires field (2027-10-01) has to be renewed before that date.

Related to MRGFY-10192

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com

docs.mergify.com now serves an RFC 9116 `/.well-known/security.txt`
whose only contact is the HackerOne program, with `Policy` pointing to
the security page's "Vulnerability Disclosure" section. The path is
excluded in `_routes.json` so it is served as a static `text/plain` file
without going through the Pages middleware.

The support page gains a "Report a Security Vulnerability" section that
sends researchers to HackerOne instead of the support queue.

The `Expires` field (2027-10-01) has to be renewed before that date.

Related to MRGFY-10192

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Change-Id: I87f609e7d5d4cf23e76ae8baf7638a5a42397bab
Copilot AI balanced review requested due to automatic review settings October 8, 2026 09:47
@mergify
mergify Bot deployed to Mergify Merge Protections October 8, 2026 09:48 Active
@mergify

mergify Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Merge Protections

🟢 All 5 merge protections satisfied — ready to merge.

Show 5 satisfied protections

🟢 👀 Review Requirements

  • any of:
    • #approved-reviews-by >= 1
    • author = dependabot[bot]
    • author = renovate[bot]
    • all of:
      • author = mergify-ci-bot
      • -head ~= ^docs-agent/

🟢 Enforce conventional commit

Make sure that we follow https://www.conventionalcommits.org/en/v1.0.0/

  • title ~= ^(fix|feat|internal|docs|style|refactor|perf|test|build|ci|chore|revert|ui)(?:\(.+\))?!?:

🟢 🔎 Reviews

  • #changes-requested-reviews-by = 0
  • #review-requested = 0
  • #review-threads-unresolved = 0

🟢 📕 PR description

  • body ~= (?ms:.{48,})

🟢 🚦 Auto-queue

When all merge protections are satisfied, this pull request will be queued automatically.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@JulianMaurin
JulianMaurin marked this pull request as ready for review October 8, 2026 09:54
@mergify

mergify Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Merge Queue Status

This pull request spent 2 minutes 59 seconds in the queue, including 2 minutes 38 seconds running CI.

Required conditions to merge

@mergify mergify Bot added the queued label Oct 8, 2026
@mergify mergify Bot mentioned this pull request Oct 8, 2026
36 of 49 tasks
@mergify
mergify Bot merged commit ea9ff88 into main Oct 8, 2026
13 of 14 checks passed
@mergify
mergify Bot deleted the devs/JulianMaurin/MRGFY-10192/serve-security-txt-point-support-page-bug-bounty--87f609e7 branch October 8, 2026 09:57
@mergify mergify Bot removed the queued label Oct 8, 2026

This branch was successfully deployed

1 active deployment
Mergify Merge Protections — 7269f700 Deployed Oct 8, 2026 by mergify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants