Skip to content

Add SECURITY.md — enable private vulnerability reporting#22

Open
abcgco wants to merge 2 commits intoformulahendry:mainfrom
abcgco:main
Open

Add SECURITY.md — enable private vulnerability reporting#22
abcgco wants to merge 2 commits intoformulahendry:mainfrom
abcgco:main

Conversation

@abcgco
Copy link

@abcgco abcgco commented Mar 16, 2026

Summary

Add SECURITY.md with instructions for responsible vulnerability disclosure via GitHub Private Vulnerability Reporting (PVR).

PVR allows security researchers to report vulnerabilities privately through GitHub, keeping details confidential until a fix is ready. As a CNA, GitHub can assign CVE IDs directly through this workflow.

@abcgco
Copy link
Author

abcgco commented Mar 18, 2026

Hi! Could you also enable Private Vulnerability Reporting in the repo settings?

Settings → Code security → Private vulnerability reporting → Enable

Once it's active, I can submit security findings through GitHub's secure channel. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant