Skip to content

Commit b27950c

Browse files
authored
security: Indicate that a draft security advisory is insufficient notification
1 parent 55e6d57 commit b27950c

1 file changed

Lines changed: 7 additions & 1 deletion

File tree

SECURITY.md

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,4 +5,10 @@
55
Until Trillium reaches 1.0, only the most recent release will be certainly be supported for security updates, but an effort will be made to backport critical patches when possible.
66

77
## Reporting a Vulnerability
8-
To report a vulnerability, email [hi@jbr.me](mailto:hi@jbr.me)
8+
9+
To report a vulnerability, email [hi@jbr.me](mailto:hi@jbr.me) and/or contact me on [signal](https://signal.group/#CjQKIAarILo8OPFVt2qMCYgtDsPwOwwf_zVkZcDi7HEnF-BUEhAOAw28LIdxCfjbSiOJ36jB). The latter is an experiment, so please follow up by email additionally for now.
10+
11+
Feel free to [draft a GitHub Security Advisory](https://github.com/trillium-rs/trillium/security/advisories/new) in addition to the above.
12+
13+
> [!IMPORTANT]
14+
> Please do not _exclusively_ file a GitHub security advisory without also reaching out on another channel. GitHub's notifications for draft security advisories are inadequate and too easily missed.

0 commit comments

Comments
 (0)