docs: link the vulnerability report form instead of describing it - #18
Merged
Conversation
Scorecard scores SecurityPolicy 4 of 10 with `Warn: no linked content found`, and the correlation across the four repositories here is exact: the two with no links in SECURITY.md are flagged, the two with one are not. The link is worth more than the score. The policy said "use the Report a vulnerability button in the Security tab", which describes where a feature lives rather than taking someone there — and private reporting was only enabled today, so `…/security/advisories/new` is now a real door. Someone holding a vulnerability should not have to go looking for it. It also now says that reporting is private, which is the reason not to open an issue and was left implicit before. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scorecard's
SecurityPolicycheck scores this repository 4 out of 10, withWarn: no linked content found. The correlation across the four repositories inthis account is exact — the two with zero links in
SECURITY.mdare flagged, thetwo with one are not.
The link matters more than the score
The policy said "use the Report a vulnerability button in the Security tab".
That describes where a feature lives instead of taking someone there — and private
vulnerability reporting was only switched on today, so
…/security/advisories/newis now a real door.
The difference is between naming a feature and giving someone the way in. Someone
holding a vulnerability should not have to go looking.
The wording also states that reporting is private, because that is the reason not
to open an issue and it was previously left implicit.
Verification
Documentation only.
qualityandverify:packagefor completeness.🤖 Generated with Claude Code