Join our community: https://t.me/+DOylgFv1jyJlNzM0
Why this matters
SECURITY.md describes the supported versions and general policy but does not explain the concrete mechanism (email vs GitHub Security Advisories) a researcher should use to privately report a vulnerability, which risks a report landing in a public issue instead.
Acceptance criteria
Files to touch
SECURITY.md
CONTRIBUTING.md
Out of scope
Does not change the actual disclosure/triage process itself.
Why this matters
SECURITY.md describes the supported versions and general policy but does not explain the concrete mechanism (email vs GitHub Security Advisories) a researcher should use to privately report a vulnerability, which risks a report landing in a public issue instead.
Acceptance criteria
Files to touch
SECURITY.mdCONTRIBUTING.mdOut of scope
Does not change the actual disclosure/triage process itself.