- SECURITY.md: add Supported Versions table; reword SLA paragraph as
a bullet list per reviewer suggestion
- bug_report.yml: render reproduction textarea as shell so commands and
JSON get syntax highlighting, matching the logs field
- question.yml: add transport and install_method dropdowns mirroring
bug_report.yml so setup questions capture the same context
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Surface GitHub's native private reporting workflow as the primary
disclosure channel, with security@astrolabecloud.com kept as a fallback
for reporters without a GitHub account. Updates SECURITY.md, the README
Security section, the issue-template config link, and the bug-template
warning banner.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Add a security policy directing private vulnerability reports to
security@astrolabecloud.com instead of public issues, and update the
README's Security section to point at it.
Add structured issue forms under .github/ISSUE_TEMPLATE/ covering bugs,
feature requests, questions, and documentation, plus a config.yml that
disables blank issues and routes security reports and open-ended
questions to the appropriate channels. The bug template captures
fields most commonly missing from past reports (server/Nextcloud/app
versions, deployment mode, transport, MCP client).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>