From c58ddf8eadcc26df1f68daff681a20e226be7045 Mon Sep 17 00:00:00 2001 From: mescon <5875228+mescon@users.noreply.github.com> Date: Mon, 14 Sep 2026 22:57:00 +0200 Subject: [PATCH] docs(security): link the private report form by its address The policy told readers to find the form through the Security tab and nothing else. The address is now in the file, for readers and for the tools that judge a policy by whether it links anywhere at all. --- SECURITY.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/SECURITY.md b/SECURITY.md index 562408e..fafc285 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -12,7 +12,8 @@ Please report suspected vulnerabilities privately, not in a public issue. - Preferred: open a private report through GitHub's **Security** tab on this repository (**Report a vulnerability**), which opens a private advisory - only the maintainer can see. + only the maintainer can see: + - If you cannot use that, open an ordinary issue that says only that you have a security report and how the maintainer can reach you privately; do not put the details in the issue.