Revise reporting security issues section#348
Conversation
Updated the section on reporting security issues to emphasize responsible disclosure practices and provide additional reporting channels.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
I'm starting a first review of this pull request. You can view the conversation on Warp. I completed the review and no human review was requested for this pull request. Comment Powered by Oz |
There was a problem hiding this comment.
Overview
This PR revises the security vulnerability reporting section on the contributing page to emphasize private responsible disclosure and add a GitHub Security Advisory channel. The change is directionally sound; I found two non-blocking wording improvements and no security issues in the docs diff.
Concerns
- The heading reads awkwardly without an article.
- The new reporting instructions drop the concrete details reporters should include, which may create extra back-and-forth.
Verdict
Found: 0 critical, 0 important, 2 suggestions
Approve with nits
Comment /oz-review on this pull request to retrigger a review (up to 3 times on the same pull request).
Powered by Oz
Co-authored-by: oz-for-oss[bot] <277970191+oz-for-oss[bot]@users.noreply.github.com>
Co-authored-by: oz-for-oss[bot] <277970191+oz-for-oss[bot]@users.noreply.github.com>
Summary
Updated the section on reporting security issues to emphasize responsible disclosure practices and provide additional reporting channels.
The current kapa responses were based on simple instructions and not as detailed.