* docs(118): scaffold docs/security/baseline.md with section structure
Creates docs/security/ directory and baseline.md with the full nine-section
RFC skeleton for the open-gsd org-level security baseline.
Sections: Status & scope, Minimum security controls (2.1–2.6), Incident-audit
checklist (NIST SP 800-61 Rev. 2), Reporting format, Ownership model, Rollout
plan, KPIs, Follow-up tracking checklist, References.
Source: https://csrc.nist.gov/publications/detail/sp/800-218/final (SSDF v1.1)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* docs(118): link baseline from SECURITY.md
Adds pointer section "Org-level security baseline" to SECURITY.md pointing
to docs/security/baseline.md. Per D1: no content duplication — SECURITY.md
retains its vulnerability-reporting focus; the new section links out only.
Source: https://docs.github.com/en/code-security/security-advisories
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* docs(118): fill PR #136 reference for reproducible env bootstrap (#117)
PR #136 was opened for #117 after this RFC was drafted; updating the
cross-reference. Replaces two "TBD" / "PR for #117" placeholders at
§ 2.5 and § 7 rollout table, and marks the §8 tracking checkbox as done.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>