Skip to content

docs: add SECURITY.md for private vulnerability reporting - #5493

Open
Solaris-star wants to merge 1 commit into
chatchat-space:masterfrom
Solaris-star:docs/5492-security-policy
Open

docs: add SECURITY.md for private vulnerability reporting#5493
Solaris-star wants to merge 1 commit into
chatchat-space:masterfrom
Solaris-star:docs/5492-security-policy

Conversation

@Solaris-star

Copy link
Copy Markdown

Summary

Researchers currently have no documented private security contact (SECURITY.md missing; private vulnerability reporting not obvious). This adds a root SECURITY.md describing supported versions and private disclosure channels so vulnerabilities are not filed as public issues.

Testing

  • Docs-only change

Fixes #5492

Provide a clear private disclosure path so researchers are not forced
to file public issues. Prefer GitHub private reporting or the project
Telegram group for maintainer contact.

Fixes chatchat-space#5492

Signed-off-by: Solaris-star <820622658@qq.com>
@dosubot dosubot Bot added the size:M This PR changes 30-99 lines, ignoring generated files. label Jul 21, 2026
@noyp-lasso

Copy link
Copy Markdown

Flagging some urgency: the issue that we are about to report is critical, and there's still no private channel to finalize an advisory through. It would help a lot if you could merge this PR and enable Private Vulnerability Reporting (Settings → Code security and analysis → Private vulnerability reporting) so the full report and a CVE can be handled properly.

One small suggestion for the SECURITY.md itself: alongside the GitHub private-reporting link, listing a security contact email as a fallback would make it easier for researchers to reach you even before PVR is on.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M This PR changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Request: enable Private Vulnerability Reporting / provide a security contact

2 participants