docs(security): prefer GitHub private vulnerability reporting
Surface GitHub's native private reporting workflow as the primary disclosure channel, with security@astrolabecloud.com kept as a fallback for reporters without a GitHub account. Updates SECURITY.md, the README Security section, the issue-template config link, and the bug-template warning banner. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
8cc84ac08b
commit
d6362dc773
@@ -248,7 +248,7 @@ This project takes security seriously:
|
||||
- No credential storage in OAuth mode
|
||||
- Regular security assessments
|
||||
|
||||
Found a security issue? **Do not open a public GitHub issue.** Please report it privately by emailing **security@astrolabecloud.com**. See [SECURITY.md](./SECURITY.md) for details.
|
||||
Found a security issue? **Do not open a public GitHub issue.** Use GitHub's [private vulnerability reporting](https://github.com/cbcoutinho/nextcloud-mcp-server/security/advisories/new), or email **security@astrolabecloud.com** if you can't use GitHub. See [SECURITY.md](./SECURITY.md) for details.
|
||||
|
||||
## License
|
||||
|
||||
|
||||
Reference in New Issue
Block a user