Skip to content

docs: clarify security audit coverage boundaries - #37

Open
XiongziqiangA wants to merge 1 commit into
cloudflare:mainfrom
XiongziqiangA:patch-1
Open

XiongziqiangA wants to merge 1 commit into
cloudflare:mainfrom
XiongziqiangA:patch-1

Conversation

@XiongziqiangA

Copy link
Copy Markdown

Summary

  • document that the audit does not query live advisory or CVE databases
  • explain how external advisory facts should remain needs_validation unless supplied locally
  • clarify that the security-focused coverage ledger is not a guarantee of general domain correctness

Testing

Documentation-only change; verified the rendered Markdown and comparison diff.

Relates to #20.

Document that live advisory/CVE lookups are outside the sandbox and that the security-focused coverage ledger does not guarantee general domain correctness.

Relates to cloudflare#20.
@wyaaa671-afk

This comment has been minimized.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants