From ed4ee141d2da978af66e65c133dcb21ea24d99f0 Mon Sep 17 00:00:00 2001 From: Daniel Bae <157205701+MrBeldum@users.noreply.github.com> Date: Mon, 5 Oct 2026 13:09:29 -0700 Subject: [PATCH] docs: Offer private vulnerability reporting in the issue chooser SECURITY.md points reporters at the private advisory form, but there was no .github/ISSUE_TEMPLATE/config.yml, so the issue chooser showed only public templates. Add a contact link to the enabled private vulnerability reporting form so the private route is visible where a reporter decides how to file. --- .github/ISSUE_TEMPLATE/config.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 .github/ISSUE_TEMPLATE/config.yml diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml new file mode 100644 index 0000000..3aeb674 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -0,0 +1,13 @@ +# The issue chooser is where a reporter decides how to file. SECURITY.md asks +# that a vulnerability never be a public issue, so the private route has to be +# visible here, next to the public templates, not only in a file the reporter +# may never open. +# +# Blank issues stay enabled: that was the behaviour before this file existed, +# and this file only adds a route, it does not take one away. + +blank_issues_enabled: true +contact_links: + - name: Report a security vulnerability + url: https://github.com/plannotator/tot/security/advisories/new + about: Do not open a public issue. Report it privately here. See SECURITY.md.