Wiki/.github/ISSUE_TEMPLATE/security.md
Corentin JOGUET 668576cdc4 chore: initial commit — formation-hub conception phase
Conception complete (Phase 0) pour formation-hub Acadenice :

- 19 docs Merise Agile + UML + GitOps + plans (tests/deploy/ops/api)
  cf docs/00-readme.md pour l'index complet
- Stack Docker compose (Docmost + Baserow + Postgres + Redis + MinIO local FS)
  compose.yml + compose.staging.yml + compose.prod.yml
- CI/CD GitHub Actions skeleton (ci, deploy-staging, deploy-prod)
- Bridge service skeleton (Hono + TS + Biome + Vitest + zod + pino)
- Templates GitHub : PR + 3 issue types + CODEOWNERS + dependabot.yml
- Scripts ops : healthcheck, backup quotidien, smoke-test post-deploy
- LICENSE AGPL-3.0 + SECURITY.md + CONTRIBUTING.md + CHANGELOG.md
- Diagramme drawIO archi infra (XML importable dans diagrams.net)

Decisions structurelles enregistrees :
- Scope CFA + Agence avec entite PERSONNE pivot multi-roles (ADR-001)
- Stack composite Docmost AGPL + Baserow MIT + bridge custom (ADR-001)
- Path B : UX quasi-unified via Tiptap node-views custom (ADR-002)
- Monorepo trunk-based development (ADR-003)
- Postgres separe Docmost/Baserow (ADR-004)
- Bridge stack Node 22 + Hono (ADR-005)
- Repo neuf prefere a fork Docmost
- Prod-like des le jour 1 (pas MVP)
2026-05-07 12:16:19 +02:00

37 lines
616 B
Markdown

---
name: Security report (PUBLIC issue NON RECOMMANDE)
about: Pour signaler une vulnerabilite, voir SECURITY.md
title: "[SEC] "
labels: security
assignees: Imugiii
---
## STOP
**Si tu signales une vulnerabilite reelle, NE PAS ouvrir une issue publique.**
Contacte : **security@acadenice.fr**
Voir `SECURITY.md` pour le process complet.
---
## Si c'est une suggestion non-sensible (hardening, best practice)
### Description
<!-- Quoi -->
### Risk assessment
- CVSS score estime :
- Vector :
- Impact si exploite :
### Recommandation
<!-- Comment fixer -->
### References
<!-- CVE, CWE, OWASP, etc. -->