Surface GitHub's native private reporting workflow as the primary disclosure channel, with security@astrolabecloud.com kept as a fallback for reporters without a GitHub account. Updates SECURITY.md, the README Security section, the issue-template config link, and the bug-template warning banner. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1.1 KiB
1.1 KiB
Security Policy
Reporting a Vulnerability
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Preferred: GitHub Private Vulnerability Reporting
Use GitHub's built-in private reporting workflow:
This opens a private draft security advisory visible only to the repository maintainers. You can also reach the same form from the Security tab → Report a vulnerability.
Fallback: Email
If you cannot use GitHub's private reporting (for example, you don't have a GitHub account), email:
What to include
Whichever channel you use, please include as much of the following as you can to help us triage:
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof-of-concept code, if applicable)
- The version(s) of the project affected
- Any known mitigations or workarounds
We will acknowledge receipt and work with you on coordinated disclosure.