docs(security): prefer GitHub private vulnerability reporting

Surface GitHub's native private reporting workflow as the primary
disclosure channel, with security@astrolabecloud.com kept as a fallback
for reporters without a GitHub account. Updates SECURITY.md, the README
Security section, the issue-template config link, and the bug-template
warning banner.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Chris Coutinho
2026-04-29 23:09:39 +02:00
co-authored by Claude Opus 4.7
parent 8cc84ac08b
commit d6362dc773
4 changed files with 22 additions and 10 deletions
+17 -5
View File
@@ -2,17 +2,29 @@
## Reporting a Vulnerability
**Please do not report security vulnerabilities through public GitHub issues.**
**Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.**
If you discover a security vulnerability in this project, report it privately by emailing:
### Preferred: GitHub Private Vulnerability Reporting
Use GitHub's built-in private reporting workflow:
➡️ **[Report a vulnerability](https://github.com/cbcoutinho/nextcloud-mcp-server/security/advisories/new)**
This opens a private draft security advisory visible only to the repository maintainers. You can also reach the same form from the **Security** tab → **Report a vulnerability**.
### Fallback: Email
If you cannot use GitHub's private reporting (for example, you don't have a GitHub account), email:
**security@astrolabecloud.com**
Please include as much of the following information as possible to help us triage your report:
### What to include
Whichever channel you use, please include as much of the following as you can to help us triage:
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue (proof-of-concept code, if applicable)
- Steps to reproduce (proof-of-concept code, if applicable)
- The version(s) of the project affected
- Any known mitigations or workarounds
We will acknowledge receipt of your report and work with you on coordinated disclosure.
We will acknowledge receipt and work with you on coordinated disclosure.