The community standards checklist for this repo has two items still open: a code of conduct and a security policy (SECURITY.md). Everything else (README, contributing guide, license, issue and PR templates) is already in place.
On the security side, CONTRIBUTING.md already points people to security@anthropic.com for private reports, so a SECURITY.md would mostly just move that into the GitHub-recognized file (which also turns on the "Report a vulnerability" flow). Happy to send that PR if you're open to it.
The code of conduct is the one with an actual open question: what reporting contact should the enforcement section use? That's the part an outside contributor can't fill in. And is the intent to keep these per repo, or is there an org-level policy I should just link to instead?
If it helps, I can open a PR adding a SECURITY.md (pointing at the existing security@anthropic.com address) plus the Contributor Covenant for the code of conduct, once I know what conduct contact to use. Fine to close this out if it's intentional or handled somewhere else.
The community standards checklist for this repo has two items still open: a code of conduct and a security policy (SECURITY.md). Everything else (README, contributing guide, license, issue and PR templates) is already in place.
On the security side, CONTRIBUTING.md already points people to security@anthropic.com for private reports, so a SECURITY.md would mostly just move that into the GitHub-recognized file (which also turns on the "Report a vulnerability" flow). Happy to send that PR if you're open to it.
The code of conduct is the one with an actual open question: what reporting contact should the enforcement section use? That's the part an outside contributor can't fill in. And is the intent to keep these per repo, or is there an org-level policy I should just link to instead?
If it helps, I can open a PR adding a SECURITY.md (pointing at the existing security@anthropic.com address) plus the Contributor Covenant for the code of conduct, once I know what conduct contact to use. Fine to close this out if it's intentional or handled somewhere else.