docs: add MIT license, security policy, and README legal section

Include SECURITY.md for private vulnerability reporting; fix CONTRIBUTING upstream URL.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-05-04 12:53:56 +08:00
parent 25e36d67c2
commit 19e51e2c12
4 changed files with 48 additions and 1 deletions

21
SECURITY.md Normal file
View file

@ -0,0 +1,21 @@
# Security policy
## Supported versions
Security fixes are applied on the default branch (`main`) when practical. Use the latest commit for deployments.
## Reporting a vulnerability
Please **do not** open a public GitHub issue for undisclosed security problems.
Use **GitHub private vulnerability reporting** for this repository:
[Submit a private security advisory](https://github.com/hansjone/oclaw/security/advisories/new)
Include:
- A short description of the impact
- Steps to reproduce (or proof-of-concept) if you can share them safely
- Affected component or path (if known)
We will treat reports as confidential and coordinate a fix and disclosure timeline with you when possible.