Skip to content

docs: Offer private vulnerability reporting in the issue chooser - #385

Open
MrBeldum wants to merge 1 commit into
NHSDigital:mainfrom
MrBeldum:docs/security-contact-link
Open

MrBeldum wants to merge 1 commit into
NHSDigital:mainfrom
MrBeldum:docs/security-contact-link

Conversation

@MrBeldum

@MrBeldum MrBeldum commented Oct 5, 2026

Copy link
Copy Markdown

Description

SECURITY.md asks reporters to use the private vulnerability reporting form and not to open a public issue. But there is no .github/ISSUE_TEMPLATE/config.yml, so the issue chooser has no contact link pointing at that private route. A reporter has to find SECURITY.md on their own.

This adds .github/ISSUE_TEMPLATE/config.yml with a "Report a security vulnerability" contact link to the private advisory form, so the private route shows up in the chooser. blank_issues_enabled: true keeps the current behaviour. The file only adds a route.

Private vulnerability reporting is already enabled for this repository (GET /repos/NHSDigital/software-engineering-quality-framework/private-vulnerability-reporting returns {"enabled":true}).

  • Documentation update

How Has This Been Tested?

  • Parsed the new file as YAML (blank_issues_enabled: true, one contact_links entry with name/url/about).
  • GitHub config only, no application code changed.

SECURITY.md already asks reporters to use private vulnerability reporting
instead of a public issue. Add a contact_link so that route appears in the
issue chooser next to any public templates.
@MrBeldum
MrBeldum requested a review from a team as a code owner October 5, 2026 20:02
@sonarqubecloud

sonarqubecloud Bot commented Oct 5, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant