Skip to content

Document both vulnerability reporting channels - #1088

Merged
mensfeld merged 1 commit into
masterfrom
fix/44907-vulnerability-reporting-channels
Aug 19, 2026
Merged

Document both vulnerability reporting channels#1088
mensfeld merged 1 commit into
masterfrom
fix/44907-vulnerability-reporting-channels

Conversation

@coipond-writer

Copy link
Copy Markdown
Contributor

Summary

Pro/Compliance-Certifications.md claimed vulnerability reporting only happens through GitHub's private vulnerability reporting program, but SECURITY.md documents an email-only channel (contact@karafka.io). Per the Redmine discussion, both channels are genuinely live simultaneously - GitHub PVR is confirmed enabled on the repo, and SECURITY.md is confirmed current and unchanged. Updated the wiki to mention both.

Per Redmine #44907, following Maciej's proposed wording ("via email OR via GitHub's private vulnerability reporting program").

Scope note

Only the wiki was touched here. Whether SECURITY.md itself should also mention the GitHub PVR option (currently email-only) was raised as a separate open question in the ticket discussion and left for a separate decision - not done in this PR.

Test plan

  • npm run lint - 0 issues across all 196 files

Wiki claimed GitHub private vulnerability reporting was the only
channel, but SECURITY.md documents email-only reporting to
contact@karafka.io. Both channels are actually live simultaneously
(GitHub PVR confirmed enabled via the repo's API, SECURITY.md confirmed
current), so the wiki now lists both instead of just one.
@mensfeld
mensfeld merged commit 62b0a35 into master Aug 19, 2026
4 checks passed
@mensfeld
mensfeld deleted the fix/44907-vulnerability-reporting-channels branch August 19, 2026 08:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant