docs: add LEGAL.md as a single index for legal/compliance docs - #791
Conversation
Bundle license, code of conduct, security, support, and regulatory-compliance documentation links (LICENSE, CODE_OF_CONDUCT.md, SECURITY.md, SUPPORT.md, docs/security-support-policy.md, docs/security-compliance-categories.md, docs/support-policy.md, docs/cra-scope-decision.md, docs/cra-incident-runbook.md) behind a single LEGAL.md entry point, so README's 'Please read these first' and License sections link to one document instead of listing them individually. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
SemTiOne
left a comment
There was a problem hiding this comment.
LGTM. The index makes sense, and I don't see a legal issue introduced by this PR since the underlying license, security, support, and CRA documents are unchanged.
One small concern though, I would keep SECURITY.md as a direct README entry as well. For vulnerability reporters, adding an extra hop through LEGAL.md slightly reduces discoverability, while the other documents can still be consolidated there.
Add SECURITY.md as its own entry in README's "Please read these first" list, alongside LEGAL.md, so vulnerability reporting is discoverable directly from the README instead of only nested inside the LEGAL.md index. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Reintroduced SECURITY.md as a direct entry in README's "Please read these first" list (alongside LEGAL.md) so reporting a vulnerability is one click away from the README instead of only being discoverable via the LEGAL.md index. Pushed in baab077. |
|



Per discussion: bundles license/security/support/compliance docs behind one entry point instead of listing each individually in README.
What changed
LEGAL.mdat repo root indexes:LICENSE,CODE_OF_CONDUCT.md,SECURITY.md,SUPPORT.md,docs/security-support-policy.md,docs/security-compliance-categories.md,docs/support-policy.md,docs/cra-scope-decision.md,docs/cra-incident-runbook.md— each with a one-line description, no content duplicated.README.md's 'Please read these first' list now links toLEGAL.mdinstead of listingCODE_OF_CONDUCT.md/SECURITY.md/SUPPORT.md/docs/security-support-policy.mdseparately.README.md's License section now also points toLEGAL.mdfor the fuller security/support/compliance picture.None of the underlying documents were moved or rewritten — this only adds an index layer. Verified all linked paths resolve and
npx markdownlint-cli@0.49.0 LEGAL.md README.mdis clean.