Hi, I wanted to report a security issue privately, but I noticed that SECURITY.md asks researchers to report vulnerabilities via email while the email link appears to be empty:
Because I could not find a valid security contact address, I submitted the report through GitHub's private vulnerability reporting / security advisory flow instead.
Could you please confirm whether that is the preferred channel, or update SECURITY.md with the correct security contact email if email reports are preferred?
Thanks!
Hi, I wanted to report a security issue privately, but I noticed that
SECURITY.mdasks researchers to report vulnerabilities via email while the email link appears to be empty:Because I could not find a valid security contact address, I submitted the report through GitHub's private vulnerability reporting / security advisory flow instead.
Could you please confirm whether that is the preferred channel, or update
SECURITY.mdwith the correct security contact email if email reports are preferred?Thanks!