Skip to content

[Docs] SECURITY.md does not link to the vulnerability disclosure form or GitHub Security Advisories flow #1062

Description

@grantfox-oss

Join our community: https://t.me/+DOylgFv1jyJlNzM0

Why this matters

SECURITY.md describes the supported versions and general policy but does not explain the concrete mechanism (email vs GitHub Security Advisories) a researcher should use to privately report a vulnerability, which risks a report landing in a public issue instead.

Acceptance criteria

  • Add explicit instructions for reporting via GitHub Security Advisories or a listed contact
  • Cross-link SECURITY.md from CONTRIBUTING.md

Files to touch

  • SECURITY.md
  • CONTRIBUTING.md

Out of scope

Does not change the actual disclosure/triage process itself.

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave programdocsDocumentationgood first issueGood for newcomerssecuritySecurity related tasks

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions