Feature Description
[EDIT] OK just seen the thing 😄 I opened a PR associated to add a security.md file let me know what do you think!
Hey,
Wanted to suggest something, modifying the security.md of the repo to use that github feature -> https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/configuring-private-vulnerability-reporting-for-a-repository instead
It allows a private security disclosure and is used by quite some others, might help @appleboy not being the only one reciving this but shared among maintainers!
(Maybe its absolutely not what you guys want to do, but if that help... 😄 )
See the example on the trivy repo -> https://github.com/aquasecurity/trivy/security
Cheers
Feature Description
[EDIT] OK just seen the thing 😄 I opened a PR associated to add a security.md file let me know what do you think!
Hey,
Wanted to suggest something, modifying the security.md of the repo to use that github feature -> https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/configuring-private-vulnerability-reporting-for-a-repository instead
It allows a private security disclosure and is used by quite some others, might help @appleboy not being the only one reciving this but shared among maintainers!
(Maybe its absolutely not what you guys want to do, but if that help... 😄 )
See the example on the trivy repo -> https://github.com/aquasecurity/trivy/security
Cheers