Skip to content

admin: Update security instructions to emphasize reporting via GitHub#5149

Merged
lgritz merged 1 commit intoAcademySoftwareFoundation:mainfrom
lgritz:lg-security
Apr 20, 2026
Merged

admin: Update security instructions to emphasize reporting via GitHub#5149
lgritz merged 1 commit intoAcademySoftwareFoundation:mainfrom
lgritz:lg-security

Conversation

@lgritz
Copy link
Copy Markdown
Collaborator

@lgritz lgritz commented Apr 18, 2026

The security@openimageio.org is still fine, but we prefer that true vulnerability reports come via the GitHub security advisory mechanism. (That makes it easy for us to turn them into CVEs when needed, among other administrative niceties.)

The security@openimageio.org is still fine, but we prefer that true
vulnerability reports come via the GitHub security advisory mechanism.
(That makes it easy for us to turn them into CVEs when needed, among
other administrative niceties.)

Signed-off-by: Larry Gritz <lg@larrygritz.com>
@lgritz lgritz merged commit c6c80bc into AcademySoftwareFoundation:main Apr 20, 2026
3 checks passed
@lgritz lgritz deleted the lg-security branch April 21, 2026 05:18
lgritz added a commit to lgritz/OpenImageIO that referenced this pull request Apr 21, 2026
…AcademySoftwareFoundation#5149)

The security@openimageio.org is still fine, but we prefer that true
vulnerability reports come via the GitHub security advisory mechanism.
(That makes it easy for us to turn them into CVEs when needed, among
other administrative niceties.)

Signed-off-by: Larry Gritz <lg@larrygritz.com>
lgritz added a commit to lgritz/OpenImageIO that referenced this pull request Apr 23, 2026
…AcademySoftwareFoundation#5149)

The security@openimageio.org is still fine, but we prefer that true
vulnerability reports come via the GitHub security advisory mechanism.
(That makes it easy for us to turn them into CVEs when needed, among
other administrative niceties.)

Signed-off-by: Larry Gritz <lg@larrygritz.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants