diff --git a/.machine_readable/root-allow.txt b/.machine_readable/root-allow.txt index efa0e0b..8f9c3c4 100644 --- a/.machine_readable/root-allow.txt +++ b/.machine_readable/root-allow.txt @@ -20,6 +20,8 @@ AFFIRMATION.adoc # dated/signed honesty snapshot (README/EXPLAINME/AFF GOVERNANCE.adoc # governance model (validator accepts root or docs/governance/) MAINTAINERS.adoc # maintainer roster CONTRIBUTING.md # REQUIRED AT ROOT by scorecard-enforcer/openssf-compliance/quality CI (test -f, no .github fallback). The fuller copy in .github/ is GitHub's auto-discovery convention; dedupe is an owner decision (would need those CI checks updated to accept .github/). +SECURITY.adoc # current security policy; same root requirement +CONTRIBUTING.adoc # current contributor guide; the root path is hard-required by openssf-compliance.yml (test -f, exit 1, no .github/ fallback) SECURITY.md # REQUIRED AT ROOT by scorecard-enforcer CI + the security-policy contractile (test -f SECURITY.md). See CONTRIBUTING.md note re: the .github/ copy. LICENSE LICENSES/ # REUSE licence texts (MPL-2.0.txt + CC-BY-SA-4.0.txt) for the dual-licence model (code MPL-2.0 / docs CC-BY-SA-4.0)