Skip to content

Revise reporting security issues section#348

Merged
dannyneira merged 4 commits into
mainfrom
danny/update-sec-vuln-instructions
Jul 21, 2026
Merged

Revise reporting security issues section#348
dannyneira merged 4 commits into
mainfrom
danny/update-sec-vuln-instructions

Conversation

@dannyneira

Copy link
Copy Markdown
Member

Summary

Updated the section on reporting security issues to emphasize responsible disclosure practices and provide additional reporting channels.

The current kapa responses were based on simple instructions and not as detailed.

Updated the section on reporting security issues to emphasize responsible disclosure practices and provide additional reporting channels.
@cla-bot cla-bot Bot added the cla-signed label Jul 20, 2026
@vercel

vercel Bot commented Jul 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
docs Ready Ready Preview, Comment Jul 21, 2026 11:21pm

Request Review

@oz-for-oss

oz-for-oss Bot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

@dannyneira

I'm starting a first review of this pull request.

You can view the conversation on Warp.

I completed the review and no human review was requested for this pull request.

Comment /oz-review on this pull request to retrigger a review (up to 3 times on the same pull request).

Powered by Oz

@oz-for-oss oz-for-oss Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overview

This PR revises the security vulnerability reporting section on the contributing page to emphasize private responsible disclosure and add a GitHub Security Advisory channel. The change is directionally sound; I found two non-blocking wording improvements and no security issues in the docs diff.

Concerns

  • The heading reads awkwardly without an article.
  • The new reporting instructions drop the concrete details reporters should include, which may create extra back-and-forth.

Verdict

Found: 0 critical, 0 important, 2 suggestions

Approve with nits

Comment /oz-review on this pull request to retrigger a review (up to 3 times on the same pull request).

Powered by Oz

Comment thread src/content/docs/support-and-community/community/contributing.mdx Outdated
Comment thread src/content/docs/support-and-community/community/contributing.mdx Outdated
Comment thread src/content/docs/support-and-community/community/contributing.mdx Outdated
dannyneira and others added 3 commits July 21, 2026 17:18
Co-authored-by: oz-for-oss[bot] <277970191+oz-for-oss[bot]@users.noreply.github.com>
Co-authored-by: oz-for-oss[bot] <277970191+oz-for-oss[bot]@users.noreply.github.com>
@dannyneira
dannyneira merged commit ab243ae into main Jul 21, 2026
6 of 7 checks passed
@dannyneira
dannyneira deleted the danny/update-sec-vuln-instructions branch July 21, 2026 23:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants