diff --git a/SECURITY.md b/SECURITY.md index 3d20210454f4..dd33d469c873 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -7,7 +7,7 @@ As such, there is no supportability commitment. The maintainers will do the best ## Reporting a Vulnerability -Please use the "Private vulnerability reporting" feature in the GitHub repository (under the "Security" tab). +Please use the "Private vulnerability reporting" feature in the GitHub repository (under the "Security" tab) once we enable it. ⚠️ **Important:** This policy is intended for vulnerabilities in **Trivy itself** (e.g., core functionality, scanning logic, or security features).