[Docs] CHANGELOG still cites security@vigilis.nl as a reporting address #645

Closed
opened 2026-07-22 16:23:40 +00:00 by brenno · 0 comments
Owner

Found in the main loop while checking publication readiness of the repository.

Evidence: CHANGELOG.md:405 — "contactkaartje in de issuetracker verwees naar security@vigilis.nl, terwijl…". The reporting address is security@librekat.nl (SECURITY.md:20).

The line describes a fault that was fixed, so its presence may well be deliberate — the house style is to leave corrections standing. But the effect on a new reader is that grep -rn "security@" . surfaces two addresses with no indication which is current, and the wrong one is at a domain the foundation does not use for this purpose.

Why this matters: low severity, and arguably by design. Filed so the choice is made explicitly rather than by default, since the changelog is about to become public.

Proposal: either add a half-sentence making clear which address is current, or reword the entry to describe the fault without reproducing the dead address. Related: the URLs throughout COMPLIANCE.md, SECURITY.md:543-545 and CHANGELOG.md:4903 point at the pawprint.vigilis.online forge — correct today, but worth a deliberate decision about whether the canonical public address of an LibreKAT project should live on that host.

Found in the main loop while checking publication readiness of the repository. **Evidence:** `CHANGELOG.md:405` — "contactkaartje in de issuetracker verwees naar `security@vigilis.nl`, terwijl…". The reporting address is `security@librekat.nl` (`SECURITY.md:20`). The line describes a fault that was fixed, so its presence may well be deliberate — the house style is to leave corrections standing. But the effect on a new reader is that `grep -rn "security@" .` surfaces two addresses with no indication which is current, and the wrong one is at a domain the foundation does not use for this purpose. **Why this matters:** low severity, and arguably by design. Filed so the choice is made explicitly rather than by default, since the changelog is about to become public. **Proposal:** either add a half-sentence making clear which address is current, or reword the entry to describe the fault without reproducing the dead address. Related: the URLs throughout `COMPLIANCE.md`, `SECURITY.md:543-545` and `CHANGELOG.md:4903` point at the `pawprint.vigilis.online` forge — correct today, but worth a deliberate decision about whether the canonical public address of an LibreKAT project should live on that host.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
LibreKAT/Ocideck#645
No description provided.