Skip to content

docs: state the unofficial status, the real scan default, and the security route - #52

Merged
ruangraung merged 1 commit into
mainfrom
chore/launch-polish
Sep 22, 2026
Merged

ruangraung merged 1 commit into
mainfrom
chore/launch-polish

Conversation

@ruangraung

Copy link
Copy Markdown
Owner

What changed

  • The README described the scan form's max duration default as 10m. That stopped being true when the form began leaving it empty, so it now says what the form does: no limit by default, with 30s, 10m, 2h or 0 available.
  • The README states that this is an unofficial interface and is not affiliated with Perplexity AI.
  • CONTRIBUTING.md pointed at a private reporting channel that does not exist. It now points at SECURITY.md.
  • SECURITY.md is new. It names GitHub private vulnerability reporting as the route, states what is in and out of scope, and says what a useful report contains.
  • ci.yml no longer lists refactor/v2, a branch that was deleted.

Why

The repository is preparing to become public. Text that promises a channel nobody staffed is worse than no text, and a stale default is exactly the kind of claim a first reader catches in a minute.

Verification

  • Every figure was checked against the code rather than remembered: the frontend default is '' at frontend/src/hooks/useScanForm.ts:32, the backend default is "" at backend/bumblebee_gui/models.py:26, and the catalogue section matches eleven catalogues with 1,072 entries at tag v0.1.2.
  • The four screenshots were read for operator fingerprints. The only paths visible are container-internal (/host, /root/.bumblebee-gui/scans/...) and the demo fixture (/host/demo-app). No username, hostname or real home directory appears in any of them.

Docs and CI triggers only, so no test changes. The five gates run on this pull request.

…urity route

The README described the max duration default as 10m. The form leaves it empty since the change that removed the cap, so the sentence now describes what the form does.

The README also states plainly that this is an unofficial interface, and CONTRIBUTING points at SECURITY.md instead of describing a reporting channel that was never set up.

SECURITY.md is new. It names GitHub private vulnerability reporting, states what is in scope, and says what a useful report contains.

The CI triggers no longer list refactor/v2, which was deleted with the other merged branches.
@ruangraung
ruangraung merged commit e29d19c into main Sep 22, 2026
5 checks passed
@ruangraung
ruangraung deleted the chore/launch-polish branch September 22, 2026 14:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant