Skip to content

Fix SECURITY.md Using Personal Email Instead of Org Email for Security Reports #331

Description

@ALLEN-AYODEJI

Fix SECURITY.md Using Personal Email Instead of Org Email for Security Reports

Description

SECURITY.md lists alk2izeek@gmail.com (personal Gmail) for vulnerability reports. Security reports should go to a dedicated security team email or GitHub Security Advisories process, not a personal inbox.

Requirements & Context

Replace with GitHub Security Advisories link. Or set up security@trellis.eco alias. Add PGP key for encrypted reports.

Suggested Execution

Branch: ix/docs-security-contact

Implement Changes

(1) Replace email with GitHub Security Advisory link (2) Add PGP key fingerprint (3) Add expected response timeline (4) Document report handling process

Test & Commit

Verify SECURITY.md contains correct reporting process.

Example Commit Message

ix(security): replace personal email in SECURITY.md with GitHub Security Advisories for vulnerability reports

Guidelines

  • Use GitHub Security Advisories for private disclosure
  • Add PGP key for encrypted communication

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions