Skip to content

Commit ba71ff2

Browse files
committed
docs: Offer private vulnerability reporting in the issue chooser
SECURITY.md already asks reporters to use private vulnerability reporting instead of a public issue. Add a contact_link so that route appears in the issue chooser next to any public templates.
1 parent 6241aad commit ba71ff2

1 file changed

Lines changed: 13 additions & 0 deletions

File tree

‎.github/ISSUE_TEMPLATE/config.yml‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
# The issue chooser is where a reporter decides how to file. SECURITY.md asks
2+
# that a vulnerability never be a public issue, so the private route has to be
3+
# visible here, next to the public templates, not only in a file the reporter
4+
# may never open.
5+
#
6+
# Blank issues stay enabled: a report that fits neither template is still
7+
# welcome, and this file only adds a route, it does not take one away.
8+
9+
blank_issues_enabled: true
10+
contact_links:
11+
- name: Report a security vulnerability
12+
url: https://github.com/NHSDigital/software-engineering-quality-framework/security/advisories/new
13+
about: Do not open a public issue. Report it privately here. See SECURITY.md.

0 commit comments

Comments
 (0)