Github has finally added the ability for repository owners to turn on private vulnerability reporting, to make disclosing vulnerabilities in a secure manner easier for all parties involved.
https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability
The option is not enabled by default right now.
I believe having this enabled should be considered a best practice and factored into the scorecard.
Github has finally added the ability for repository owners to turn on private vulnerability reporting, to make disclosing vulnerabilities in a secure manner easier for all parties involved.
https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability
The option is not enabled by default right now.
I believe having this enabled should be considered a best practice and factored into the scorecard.