Skip to content

Commit 32fd1fb

Browse files
authored
docs(sec): use github private reports
Signed-off-by: thaddeus kuah <[email protected]>
1 parent aed983c commit 32fd1fb

File tree

1 file changed

+4
-5
lines changed

1 file changed

+4
-5
lines changed

SECURITY.md

+4-5
Original file line numberDiff line numberDiff line change
@@ -11,11 +11,10 @@ Therefore, any code in the `main` branch is supported, and a vulnerability can b
1111

1212
## Reporting a Vulnerability
1313

14-
For severe vulnerabilities that affect all instances of Nova, please do not disclose them here.
15-
Instead, contact me through the contact form [here](https://www.tkkr.dev/contact) with details about the vulnerability, and I will get back to you by email within 24 hours after you submit the form.
16-
If you would not like to be contacted by email, please state antoher way to contact you in the `Message` field.
17-
18-
For vulnerabilities that are less severe and can be publicly disclosed, please [create an issue](https://github.com/thaddeuskkr/nova/issues/new/choose) instead.
14+
**Please do not publicly disclose vulnerabilities.**
15+
16+
Instead, report a vulnerability privately [here](https://github.com/thaddeuskkr/nova/security/advisories/new).
17+
If the vulnerability you've discovered is *severe*, do also contact me using [this form](https://www.tkkr.dev/contact), and I will get back to you within 24 hours.
1918

2019
## What counts as a severe vulnerability?
2120
* Retrieval of any user information (of other users) such as passwords and emails

0 commit comments

Comments
 (0)