Fix SECURITY.md Using Personal Email Instead of Org Email for Security Reports
Description
SECURITY.md lists alk2izeek@gmail.com (personal Gmail) for vulnerability reports. Security reports should go to a dedicated security team email or GitHub Security Advisories process, not a personal inbox.
Requirements & Context
Replace with GitHub Security Advisories link. Or set up security@trellis.eco alias. Add PGP key for encrypted reports.
Suggested Execution
Branch: ix/docs-security-contact
Implement Changes
(1) Replace email with GitHub Security Advisory link (2) Add PGP key fingerprint (3) Add expected response timeline (4) Document report handling process
Test & Commit
Verify SECURITY.md contains correct reporting process.
Example Commit Message
ix(security): replace personal email in SECURITY.md with GitHub Security Advisories for vulnerability reports
Guidelines
- Use GitHub Security Advisories for private disclosure
- Add PGP key for encrypted communication
Fix SECURITY.md Using Personal Email Instead of Org Email for Security Reports
Description
SECURITY.md lists alk2izeek@gmail.com (personal Gmail) for vulnerability reports. Security reports should go to a dedicated security team email or GitHub Security Advisories process, not a personal inbox.
Requirements & Context
Replace with GitHub Security Advisories link. Or set up security@trellis.eco alias. Add PGP key for encrypted reports.
Suggested Execution
Branch: ix/docs-security-contact
Implement Changes
(1) Replace email with GitHub Security Advisory link (2) Add PGP key fingerprint (3) Add expected response timeline (4) Document report handling process
Test & Commit
Verify SECURITY.md contains correct reporting process.
Example Commit Message
ix(security): replace personal email in SECURITY.md with GitHub Security Advisories for vulnerability reports
Guidelines