Skip to content

docs: update wording for code freeze - #24

Merged
aljo242 merged 2 commits into
mainfrom
docs/example-wording
Oct 2, 2026
Merged

aljo242 merged 2 commits into
mainfrom
docs/example-wording

Conversation

@aljo242

@aljo242 aljo242 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

The worked example carried "a vulnerability" through every verb, so it read as the vulnerability being frozen and coming down. The dates belong to the repositories.

The sentence carried one subject through every verb, so it read as the
vulnerability being frozen and coming down. Splits it so the dates attach to the
repositories.
@aljo242
aljo242 requested a review from a team as a code owner October 2, 2026 18:37
@greptile-apps

greptile-apps Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[Low risk] Clarifies vulnerability disclosure timeline in security policy.

The PR should not merge until the example distinguishes public patches from the private repositories that remain available temporarily.

Findings

  1. P1 Private repositories do not go public ▶

Summary

The PR rewords the August vulnerability example so repositories, rather than the vulnerability, are described as freezing and coming down. The revised sentence also incorrectly says the private repositories go public.

Reviews (1) · Last reviewed commit: "docs: let the repositories freeze, not t..."

Comment thread SECURITY.md Outdated
reaches the private repositories the same week, is frozen on August 25, is
public on September 1, and the August repositories come down on September 15.
reaches the private repositories the same week. Those repositories freeze on
August 25, go public on September 1, and come down on September 15.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Private repositories do not go public The new sentence says the private repositories go public on September 1. The policy instead says their patches are merged into public repositories on that date, while the private repositories remain available to invited teams until September 15. Readers could mistake this for a change to who can access the private repositories.

Suggested change
August 25, go public on September 1, and come down on September 15.
August 25; their patches go public on September 1, and the private repositories come down on September 15.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

@aljo242 aljo242 changed the title docs: let the repositories freeze, not the vulnerability docs: update wording for code freeze Oct 2, 2026
The rewrite made the repositories the subject of every verb, so it read as the
private repositories becoming public on the first. They stay private until they
come down on the fifteenth; their patches are what goes public.
@aljo242
aljo242 merged commit bed6133 into main Oct 2, 2026
1 check passed
@aljo242
aljo242 deleted the docs/example-wording branch October 2, 2026 20:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant