Skip to content

docs: Offer private vulnerability reporting in the issue chooser - #11

Open
MrBeldum wants to merge 1 commit into
plannotator:mainfrom
MrBeldum:docs/issue-chooser-security-link
Open

MrBeldum wants to merge 1 commit into
plannotator:mainfrom
MrBeldum:docs/issue-chooser-security-link

Conversation

@MrBeldum

@MrBeldum MrBeldum commented Oct 5, 2026

Copy link
Copy Markdown

Summary

SECURITY.md asks reporters not to open a public issue and to report a vulnerability privately instead. But there is no .github/ISSUE_TEMPLATE/config.yml, so the issue chooser does not surface that private route. A reporter has to find SECURITY.md on their own.

This adds a "Report a security vulnerability" contact link to the private advisory form, so the private route shows up in the chooser.

Changes

  • Add .github/ISSUE_TEMPLATE/config.yml with a contact link pointing to https://github.com/plannotator/tot/security/advisories/new.
  • Keep blank_issues_enabled: true so the current behaviour doesn't change. The file only adds a route.

Docs / GitHub config only. No application code changed. Private vulnerability reporting is already enabled for this repository (GET /repos/plannotator/tot/private-vulnerability-reporting returns {"enabled":true}).

SECURITY.md points reporters at the private advisory form, but there was no
.github/ISSUE_TEMPLATE/config.yml, so the issue chooser showed only public
templates. Add a contact link to the enabled private vulnerability reporting
form so the private route is visible where a reporter decides how to file.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant