fix(security): use security@ as the reporting contact, not hello@

hello@ works, but two different addresses across sibling org repos
force a reporter finding a vulnerability to guess which one is the
security channel. security@fromaitochitta.com is the designated one.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fm8ErxAacrm5s8ZWWubgMP
This commit is contained in:
Kjell Tore Guttormsen 2026-08-21 11:22:58 +02:00
commit c362717818

View file

@ -18,7 +18,7 @@ detector, and that is a working bypass against every consumer until it is closed
Report privately by email: Report privately by email:
- **hello@fromaitochitta.com**, with `SECURITY` at the start of the subject. - **security@fromaitochitta.com**, with `SECURITY` at the start of the subject.
Pull requests are not the channel either — they are switched off on the canonical Pull requests are not the channel either — they are switched off on the canonical
repository, and not as an oversight. This repository is vendored into independent runtimes repository, and not as an oversight. This repository is vendored into independent runtimes