Skip to content

docs: add security model documentation#2455

Open
alexandre-daubois wants to merge 1 commit into
php:mainfrom
alexandre-daubois:security-model
Open

docs: add security model documentation#2455
alexandre-daubois wants to merge 1 commit into
php:mainfrom
alexandre-daubois:security-model

Conversation

@alexandre-daubois
Copy link
Copy Markdown
Member

The ecosystem security team of the foundation needs additional information on the trust model of FrankenPHP to ensure valid security reports.

This document adds information about what's considered a security issue or not in FrankenPHP, before we can run new scans on the project.

Copilot AI review requested due to automatic review settings May 29, 2026 07:38
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds security model documentation that defines FrankenPHP’s trust boundaries and clarifies which vulnerability classes belong to FrankenPHP versus applications or upstream dependencies.

Changes:

  • Adds docs/security.md covering trust boundaries, data taint, in-scope attack surfaces, and out-of-scope issues.
  • Links the security model from the root SECURITY.md.
  • Adds the new security page to llms.txt.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

File Description
SECURITY.md Adds a Security Model section linking to the new documentation.
llms.txt Adds the security model page to the documentation index.
docs/security.md Introduces the new security model and scope guidance.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread docs/security.md Outdated
Comment thread docs/security.md Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants