Skip to content

docs: clarify security standards scope - #191

Merged
mcollina merged 2 commits into
mainfrom
docs/security-parser-scope
Jul 28, 2026
Merged

docs: clarify security standards scope#191
mcollina merged 2 commits into
mainfrom
docs/security-parser-scope

Conversation

@mcollina

@mcollina mcollina commented Jul 24, 2026

Copy link
Copy Markdown
Member

Summary

  • add a repository security policy aligned with the Fastify organization-wide policy
  • document the threat model, reporting and triage process, disclosure timeline, and Security Team
  • clarify that fast-uri follows RFC 3986 rather than the WHATWG URL Standard
  • classify differences caused by comparing or mixing parsers that follow different standards as outside the security scope
  • advise applications to use consistent parsing and normalization rules for security decisions and URI use

Validation

  • git show --check
  • tests not run (documentation-only change)

Trustinbtc999-hue

This comment was marked as spam.

@mcollina
mcollina merged commit 9918a26 into main Jul 28, 2026
3 checks passed
@mcollina
mcollina deleted the docs/security-parser-scope branch July 28, 2026 11:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants