Skip to content

docs: link the vulnerability report form instead of describing it - #18

Merged
kkdev92 merged 1 commit into
mainfrom
docs/link-vulnerability-report-form
Aug 12, 2026
Merged

docs: link the vulnerability report form instead of describing it#18
kkdev92 merged 1 commit into
mainfrom
docs/link-vulnerability-report-form

Conversation

@kkdev92

@kkdev92 kkdev92 commented Aug 12, 2026

Copy link
Copy Markdown
Owner

Scorecard's SecurityPolicy check scores this repository 4 out of 10, with
Warn: no linked content found. The correlation across the four repositories in
this account is exact — the two with zero links in SECURITY.md are flagged, the
two with one are not.

The link matters more than the score

The policy said "use the Report a vulnerability button in the Security tab".
That describes where a feature lives instead of taking someone there — and private
vulnerability reporting was only switched on today, so …/security/advisories/new
is now a real door.

The difference is between naming a feature and giving someone the way in. Someone
holding a vulnerability should not have to go looking.

The wording also states that reporting is private, because that is the reason not
to open an issue and it was previously left implicit.

Verification

Documentation only. quality and verify:package for completeness.

🤖 Generated with Claude Code

Scorecard scores SecurityPolicy 4 of 10 with `Warn: no linked content found`, and
the correlation across the four repositories here is exact: the two with no links
in SECURITY.md are flagged, the two with one are not.

The link is worth more than the score. The policy said "use the Report a
vulnerability button in the Security tab", which describes where a feature lives
rather than taking someone there — and private reporting was only enabled today, so
`…/security/advisories/new` is now a real door. Someone holding a vulnerability
should not have to go looking for it.

It also now says that reporting is private, which is the reason not to open an issue
and was left implicit before.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@kkdev92
kkdev92 merged commit 089ddd7 into main Aug 12, 2026
8 checks passed
@kkdev92
kkdev92 deleted the docs/link-vulnerability-report-form branch August 12, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant