There is a PR template but no .github/ISSUE_TEMPLATE/, so bug reports and feature requests arrive unstructured and security reports may bypass SECURITY.md. We should add bug-report and feature-request templates plus a config.yml that routes security reports to the private advisory flow in SECURITY.md.
Acceptance criteria
- Bug and feature templates are present with the right labels.
- The security contact link is surfaced in the chooser.
There is a PR template but no
.github/ISSUE_TEMPLATE/, so bug reports and feature requests arrive unstructured and security reports may bypassSECURITY.md. We should add bug-report and feature-request templates plus aconfig.ymlthat routes security reports to the private advisory flow inSECURITY.md.Acceptance criteria