Skip to content

docs: add LEGAL.md as a single index for legal/compliance docs - #791

Merged
RonaldHensbergen merged 2 commits into
mainfrom
docs/legal-md-index
Sep 30, 2026
Merged

RonaldHensbergen merged 2 commits into
mainfrom
docs/legal-md-index

Conversation

@RonaldHensbergen

Copy link
Copy Markdown
Owner

Per discussion: bundles license/security/support/compliance docs behind one entry point instead of listing each individually in README.

What changed

  • New LEGAL.md at repo root indexes: LICENSE, CODE_OF_CONDUCT.md, SECURITY.md, SUPPORT.md, docs/security-support-policy.md, docs/security-compliance-categories.md, docs/support-policy.md, docs/cra-scope-decision.md, docs/cra-incident-runbook.md — each with a one-line description, no content duplicated.
  • README.md's 'Please read these first' list now links to LEGAL.md instead of listing CODE_OF_CONDUCT.md/SECURITY.md/SUPPORT.md/docs/security-support-policy.md separately.
  • README.md's License section now also points to LEGAL.md for the fuller security/support/compliance picture.

None of the underlying documents were moved or rewritten — this only adds an index layer. Verified all linked paths resolve and npx markdownlint-cli@0.49.0 LEGAL.md README.md is clean.

Bundle license, code of conduct, security, support, and
regulatory-compliance documentation links (LICENSE, CODE_OF_CONDUCT.md,
SECURITY.md, SUPPORT.md, docs/security-support-policy.md,
docs/security-compliance-categories.md, docs/support-policy.md,
docs/cra-scope-decision.md, docs/cra-incident-runbook.md) behind a
single LEGAL.md entry point, so README's 'Please read these first' and
License sections link to one document instead of listing them
individually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@SemTiOne SemTiOne left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. The index makes sense, and I don't see a legal issue introduced by this PR since the underlying license, security, support, and CRA documents are unchanged.

One small concern though, I would keep SECURITY.md as a direct README entry as well. For vulnerability reporters, adding an extra hop through LEGAL.md slightly reduces discoverability, while the other documents can still be consolidated there.

Add SECURITY.md as its own entry in README's "Please read these
first" list, alongside LEGAL.md, so vulnerability reporting is
discoverable directly from the README instead of only nested inside
the LEGAL.md index.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@RonaldHensbergen

Copy link
Copy Markdown
Owner Author

Reintroduced SECURITY.md as a direct entry in README's "Please read these first" list (alongside LEGAL.md) so reporting a vulnerability is one click away from the README instead of only being discoverable via the LEGAL.md index. Pushed in baab077.

@sonarqubecloud

Copy link
Copy Markdown

@RonaldHensbergen
RonaldHensbergen merged commit 811d691 into main Sep 30, 2026
11 checks passed
@RonaldHensbergen
RonaldHensbergen deleted the docs/legal-md-index branch September 30, 2026 16:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants