From aca4c25d43b106844e796754e6d2301db7ca3c25 Mon Sep 17 00:00:00 2001 From: Vaclav Vancura Date: Tue, 19 May 2026 17:02:25 +0200 Subject: [PATCH] docs(security): document solo-maintainer incident triage (VV-517) Add Maintainers section to the security runbook with primary owner, explicit no-backup stance, and triage steps. VV-522 was canceled; this satisfies ownership fallback documentation for the hardening program. Co-Authored-By: Claude Signed-off-by: Vaclav Vancura --- docs/security/dependency-policy.md | 3 ++- docs/security/security-runbook.md | 19 ++++++++++++++++++- 2 files changed, 20 insertions(+), 2 deletions(-) diff --git a/docs/security/dependency-policy.md b/docs/security/dependency-policy.md index 976337d..a7c1274 100644 --- a/docs/security/dependency-policy.md +++ b/docs/security/dependency-policy.md @@ -56,5 +56,6 @@ See [audit-exceptions.md](./audit-exceptions.md) for the full playbook. ## Related docs -- [security-runbook.md](./security-runbook.md) — MCP preflight, fallback matrix, report template +- [security-runbook.md](./security-runbook.md) — MCP preflight, fallback matrix, maintainers / incident triage, report + template - [developer-experience-guide.md](../developer-experience-guide.md) — script reference diff --git a/docs/security/security-runbook.md b/docs/security/security-runbook.md index 4c91ad8..cadf714 100644 --- a/docs/security/security-runbook.md +++ b/docs/security/security-runbook.md @@ -3,6 +3,23 @@ Deterministic security workflow for Blit-Tech repos when MCP scanners are healthy, degraded, or unavailable. Use with the `/security-run` skill and `pnpm security:mcp-preflight`. +## Maintainers + +| Role | Contact / owner | Notes | +| ------------------- | ----------------------------------------------------- | ---------------------------------------------------------------------- | +| Primary security | [@vancura](https://github.com/vancura) (`CODEOWNERS`) | Sole maintainer for `blit-tech` and `blit-tech-demos` (May 2026). | +| Backup / escalation | _None_ (solo project) | No secondary on-call; treat delayed response as accepted project risk. | + +**Incident triage (solo maintainer):** + +1. Open or triage a [GitHub issue](https://github.com/vancura/blit-tech/issues) with label `security` when available. +2. Run [Repo-native commands](#repo-native-commands) for the affected repo (`pnpm security:audit`, `pnpm preflight`). +3. Follow [dependency-policy.md](./dependency-policy.md) for CI failures or temporary risk acceptance. +4. Record findings using the [Report template](#report-template) (Linear comment or issue body). + +Bus-factor evidence (optional): run the `security-ownership-map` skill and attach `summary.json` to hardening reviews. +VV-522 (backup-owner process) was canceled; this section is the documented fallback instead of a fictional backup owner. + ## When to run - Before a comprehensive security assessment or hardening pass. @@ -75,7 +92,7 @@ When Opsera `compliance-audit` MCP is unavailable, gather evidence manually: | Secrets in repo | `.gitignore`, hooks blocking `.env`; `rg` for hardcoded tokens (no secret values in reports) | | CI integrity | `.github/workflows/*.yml` — pinned actions, least privilege | | Deploy headers (demos) | `blit-tech-demos/public/_headers`, `curl -I` on deployed URLs | -| Ownership / bus factor | `security-ownership-map` skill output (`summary.json`) | +| Ownership / bus factor | [Maintainers](#maintainers) (solo); optional `security-ownership-map` skill output (`summary.json`) | | MCP governance | `pnpm security:mcp-preflight --governance-only` | ## Repo-native commands -- 2.51.2