Context
The encrypted vulnerability-disclosure channel is non-operational:
SECURITY.md:20 contains the literal string <PICO_PGP_FINGERPRINT_TODO>.
pgp-key.asc.placeholder sits at the repository root; there is no pgp-key.asc.
SECURITY.md:22-25 already documents that PGP-encrypted email is "not yet accepted" until the placeholder is replaced.
Reporters with a confidential vulnerability are funnelled into the GitHub private advisory channel, which is fine as a fallback but should not be the only option for v1 GA.
Acceptance criteria
Severity
Critical — GA blocker. Cheap to fix (operator hours, not engineering weeks); ungated reduces credibility for serious researchers.
Evidence pointers
final_readiness_report.html §10.3 DOC-01, §12.
SECURITY.md:20-25, pgp-key.asc.placeholder, .github/workflows/security-md-lint.yml.
Context
The encrypted vulnerability-disclosure channel is non-operational:
SECURITY.md:20contains the literal string<PICO_PGP_FINGERPRINT_TODO>.pgp-key.asc.placeholdersits at the repository root; there is nopgp-key.asc.SECURITY.md:22-25already documents that PGP-encrypted email is "not yet accepted" until the placeholder is replaced.Reporters with a confidential vulnerability are funnelled into the GitHub private advisory channel, which is fine as a fallback but should not be the only option for v1 GA.
Acceptance criteria
pgp-key.asc(replacing the.placeholderfile in the same PR).SECURITY.md:20in the same atomic commit.docs/runbooks/security-disclosure.mdupdated with the operator key-custody location and rotation procedure.security-md-lint.ymlcontinues to pass (it enforces atomicity between fingerprint and key file presence).Severity
Critical — GA blocker. Cheap to fix (operator hours, not engineering weeks); ungated reduces credibility for serious researchers.
Evidence pointers
final_readiness_report.html§10.3 DOC-01, §12.SECURITY.md:20-25,pgp-key.asc.placeholder,.github/workflows/security-md-lint.yml.