From 77d3a15282441f4f1c404e9b91031f715b480f25 Mon Sep 17 00:00:00 2001 From: Wei Wang Date: Thu, 1 Oct 2026 09:47:58 -0400 Subject: [PATCH] Tell a security researcher where to report The vscode repo that consumes this one has carried a SECURITY.md since its first content commit; this repo, public and separately reportable, had none, so GitHub offered no "Report a vulnerability" path and a researcher landing here had to guess an address. Copy the policy verbatim rather than word a second one: the reporting channel is MathWorks', not this repo's, and two texts that drift would be worse than one. --- SECURITY.md | 6 ++++++ 1 file changed, 6 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..2fa158c --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,6 @@ +# Reporting Security Vulnerabilities + +If you believe you have discovered a security vulnerability, please report it to +[security@mathworks.com](mailto:security@mathworks.com). Please see +[MathWorks Vulnerability Disclosure Policy for Security Researchers](https://www.mathworks.com/company/aboutus/policies_statements/vulnerability-disclosure-policy.html) +for additional information.