[Docs] CHANGELOG still cites security@vigilis.nl as a reporting address #645
Labels
No labels
accepted
bug
declined
docs
duplicate
enhancement
good first issue
in-progress
needs-info
privacy
security
triage
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
LibreKAT/Ocideck#645
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found in the main loop while checking publication readiness of the repository.
Evidence:
CHANGELOG.md:405— "contactkaartje in de issuetracker verwees naarsecurity@vigilis.nl, terwijl…". The reporting address issecurity@librekat.nl(SECURITY.md:20).The line describes a fault that was fixed, so its presence may well be deliberate — the house style is to leave corrections standing. But the effect on a new reader is that
grep -rn "security@" .surfaces two addresses with no indication which is current, and the wrong one is at a domain the foundation does not use for this purpose.Why this matters: low severity, and arguably by design. Filed so the choice is made explicitly rather than by default, since the changelog is about to become public.
Proposal: either add a half-sentence making clear which address is current, or reword the entry to describe the fault without reproducing the dead address. Related: the URLs throughout
COMPLIANCE.md,SECURITY.md:543-545andCHANGELOG.md:4903point at thepawprint.vigilis.onlineforge — correct today, but worth a deliberate decision about whether the canonical public address of an LibreKAT project should live on that host.