From 593efcac5b028c0b6d3cb69c22c2763d68f6176e Mon Sep 17 00:00:00 2001 From: "J.D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 18 Sep 2026 16:24:22 +0000 Subject: [PATCH] chore(root): allowlist the root guide and security policy MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Both are hard-required at the root by openssf-compliance.yml (test -f, exit 1, with no .github/ fallback), so they cannot be relocated without weakening that check. The allowlist named the .md forms instead of the .adoc files that actually exist. Additions only — the same correction landed in the other repos carrying this drift. --- .machine_readable/root-allow.txt | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.machine_readable/root-allow.txt b/.machine_readable/root-allow.txt index efa0e0b..8f9c3c4 100644 --- a/.machine_readable/root-allow.txt +++ b/.machine_readable/root-allow.txt @@ -20,6 +20,8 @@ AFFIRMATION.adoc # dated/signed honesty snapshot (README/EXPLAINME/AFF GOVERNANCE.adoc # governance model (validator accepts root or docs/governance/) MAINTAINERS.adoc # maintainer roster CONTRIBUTING.md # REQUIRED AT ROOT by scorecard-enforcer/openssf-compliance/quality CI (test -f, no .github fallback). The fuller copy in .github/ is GitHub's auto-discovery convention; dedupe is an owner decision (would need those CI checks updated to accept .github/). +SECURITY.adoc # current security policy; same root requirement +CONTRIBUTING.adoc # current contributor guide; the root path is hard-required by openssf-compliance.yml (test -f, exit 1, no .github/ fallback) SECURITY.md # REQUIRED AT ROOT by scorecard-enforcer CI + the security-policy contractile (test -f SECURITY.md). See CONTRIBUTING.md note re: the .github/ copy. LICENSE LICENSES/ # REUSE licence texts (MPL-2.0.txt + CC-BY-SA-4.0.txt) for the dual-licence model (code MPL-2.0 / docs CC-BY-SA-4.0)