Skip to content

feat: seed remaining empty frameworks onto the Security Map - #642

Merged
mattaereal merged 1 commit into
feat/security-map-safe-harborfrom
feat/security-map-remaining-empty
Sep 14, 2026
Merged

mattaereal merged 1 commit into
feat/security-map-safe-harborfrom
feat/security-map-remaining-empty

Conversation

@mattaereal

Copy link
Copy Markdown
Collaborator

What does this PR change?

Stacked on #641 (Safe Harbor), which stacks on #640 / #639 / #638 / #637 / #636 / #635 / #633.

Packs the remaining empty-framework list into one seed PR because each slice is small.

AI Security. Agentic tool path, prompt injection, input constraint, execution-path enforcement. Prompt templates are not a control. No incident nodes from industry reports.

ENS. Name resolution surface, spoofed resolution, L1-backed lookup, ENSIP-15 normalization. Joins misdirected transfer and signing verification. Cross-chain, interface, and contract-integration pages stay unmapped.

Guides. Overview, account-management hub, hardware security keys. Reuses phishing-resistant MFA and identity accounts. Product-level Discord/GitHub/etc. pages stay unmapped.

SSDLC. Peer code review plus existing branch protection and SDLC testing documented onto coding, review, and repository pages.

Threat modeling. Stale-model threat and a living threat-model control. Joins SSDLC design-time threat modeling.

Vulnerability disclosure. Researcher inbound path, uncontactable disclosure, published security contact, bug bounty. A bounty is not Safe Harbor. Joins Safe Harbor scope via the required security contact.

Empty-framework coverage list is now none. No related-to edges. No incident nodes.

Type of change

  • New content
  • Edit to existing content
  • Outline / structure change
  • Typo or formatting fix
  • Tooling / config

If applicable

  • Editing existing content: tagged the current contributors from the attribution list
  • Framework has a steward: asked them to review
  • Outline change: updated vocs.config.ts with the dev: true parameter
  • Want community feedback: shared this PR in our Discord

Pack AI Security, ENS, Guides, SSDLC, Threat Modeling, and Vulnerability
Disclosure as coherent first seeds. Prompt templates are not a control.
ENS resolution is not a signature. A bounty is not Safe Harbor. Product
guides, AI browsers, ENS cross-chain, and sourced incidents stay unmapped.
@mattaereal
mattaereal added this pull request to stack #643 September 14, 2026 17:24
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying frameworks with  Cloudflare Pages  Cloudflare Pages

Latest commit: 09ab0a7
Status: ✅  Deploy successful!
Preview URL: https://fcaf1993.frameworks-573.pages.dev
Branch Preview URL: https://feat-security-map-remaining.frameworks-573.pages.dev

View logs

@mattaereal
mattaereal merged commit ced60a0 into develop Sep 14, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant