Shouldn't access to `.md` files be denied, considering the `CHANGELOG.md` file contains (possibly) sensitive version information?