From 220c274108747393dbd66dabcb21df05f436c5e6 Mon Sep 17 00:00:00 2001 From: fylorn <249551762+fylorn@users.noreply.github.com> Date: Fri, 25 Sep 2026 07:36:31 +0800 Subject: [PATCH] docs(contributing): point vulnerability reports at the organization's security policy The paragraph sent reporters to a SECURITY.md this repository does not have, or to "the maintainer directly" with no address to write to. The organization-wide policy in ThinkWatchProject/.github applies to this repository and says how to reach the maintainers privately. That policy asks for one public issue: a "Security contact request" with an empty body, used while private vulnerability reporting is off. "Don't open a public issue" would contradict it, so the sentence now rules out describing the vulnerability in public, as the policy does. Co-Authored-By: Claude Opus 5.5 --- CONTRIBUTING.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index a4c9b73f..2308a33b 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -61,6 +61,7 @@ should say how you convinced yourself it doesn't leak a credential or weaken an existing check. "The tests pass" doesn't answer that — the tests didn't know about the hole either. -Please don't open a public PR or issue for a vulnerability. See -[SECURITY.md](SECURITY.md) if present, or contact the maintainer -directly. +Please don't describe a vulnerability in a public issue, PR, commit or +comment. The organization's +[security policy](https://github.com/ThinkWatchProject/.github/blob/main/SECURITY.md) +explains how to report one privately.