docs(security): add contact email, https scheme on Forgejo URL
Scorecard Security-Policy scored 4/10: no email address, bare git.fromaitochitta.com URL without scheme. Both are worth 6 of 10 points per Scorecard 5.5.0's model. Repo-specific policy text kept as-is.
This commit is contained in:
parent
246e1fc1d3
commit
2b03b8d643
1 changed files with 5 additions and 5 deletions
10
SECURITY.md
10
SECURITY.md
|
|
@ -25,12 +25,12 @@ you happened to observe.
|
|||
**Do not open a public issue for a vulnerability.** Public disclosure before a fix
|
||||
gives an attacker a window against every downstream consumer.
|
||||
|
||||
Instead, report it **privately** to the maintainer via the canonical repository on
|
||||
Forgejo:
|
||||
Instead, report it privately to <security@fromaitochitta.com> — mark the subject
|
||||
`SECURITY`.
|
||||
|
||||
- Repository: `git.fromaitochitta.com/open/llm-ingestion-pipeline-security`
|
||||
- Contact the maintainer directly through that Forgejo instance (private message /
|
||||
maintainer contact) and mark the subject `SECURITY`.
|
||||
- Canonical repository: https://git.fromaitochitta.com/open/llm-ingestion-pipeline-security
|
||||
- Alternatively, contact the maintainer directly through that Forgejo instance
|
||||
(private message / maintainer contact) and mark the subject `SECURITY`.
|
||||
|
||||
Please include:
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue