Skip to content

Commit 2abab67

Browse files
authored
Update security guidelines to point to new reporting page (#5469)
1 parent 695a94e commit 2abab67

File tree

1 file changed

+4
-7
lines changed

1 file changed

+4
-7
lines changed

security.md

+4-7
Original file line numberDiff line numberDiff line change
@@ -3,15 +3,12 @@ See also [code conventions](code-conventions.md); there are a few guidelines
33
about security of added code there.
44

55
## Reporting security issues
6-
Security issues may be reported to core team members privately e.g. on Discord.
7-
Note that this applies *only* to security issues; everything else should still
8-
be posted to issue tracker.
6+
Security issues may be reported via the GitHub private vulnerability reporting feature [here](https://github.com/SkriptLang/Skript/security/advisories/new).
7+
Note that this applies *only* to security issues; everything else should still be posted to issue tracker.
98

10-
Publicly posting security issues is also allowed, because not everyone has or
11-
wants a Discord account. We may add other channels for private reports in
12-
future.
9+
Please avoid publicly posting or discussing security issues that don't have a fix available yet.
1310

1411
## Team guidelines
1512
Everyone with push access must use two-factor authentication for their Github
1613
accounts. Should their account still be compromised, other team members should
17-
be immediately notified via Discord.
14+
be immediately notified via Discord.

0 commit comments

Comments
 (0)