Skip to content

Commit 62b0a35

Browse files
Document both vulnerability reporting channels (#1088)
Wiki claimed GitHub private vulnerability reporting was the only channel, but SECURITY.md documents email-only reporting to contact@karafka.io. Both channels are actually live simultaneously (GitHub PVR confirmed enabled via the repo's API, SECURITY.md confirmed current), so the wiki now lists both instead of just one. Co-authored-by: coipond-writer[bot] <309805719+coipond-writer[bot]@users.noreply.github.com>
1 parent 38da65f commit 62b0a35

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

Pro/Compliance-Certifications.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -81,7 +81,7 @@ While compliance certifications do **not** apply to Karafka, the project offers
8181
- **Publicly Viewable Code**: All Karafka components are publicly available on GitHub for security review. Core Karafka is open source (LGPL); Pro and Enterprise components are source-available under a commercial license, not open source
8282
- **Security Documentation**: Comprehensive guidance on securing your deployment
8383
- **Supply Chain Verification**: License gem integrity verification and checksum support
84-
- **Vulnerability Reporting**: Private vulnerability reporting program through GitHub
84+
- **Vulnerability Reporting**: Report vulnerabilities by email (see [SECURITY.md](https://github.com/karafka/karafka/blob/master/SECURITY.md)) or through GitHub's private vulnerability reporting program
8585
- **SBOM (Software Bill of Materials)**: Available for dependency tracking and security scanning
8686

8787
### Enterprise Support

0 commit comments

Comments
 (0)