From ba71ff2a3433d4ecc6946ca4bb528fd7212effb8 Mon Sep 17 00:00:00 2001 From: Daniel Bae <157205701+MrBeldum@users.noreply.github.com> Date: Mon, 5 Oct 2026 13:02:13 -0700 Subject: [PATCH] docs: Offer private vulnerability reporting in the issue chooser SECURITY.md already asks reporters to use private vulnerability reporting instead of a public issue. Add a contact_link so that route appears in the issue chooser next to any public templates. --- .github/ISSUE_TEMPLATE/config.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 .github/ISSUE_TEMPLATE/config.yml diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml new file mode 100644 index 00000000..4a908d91 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -0,0 +1,13 @@ +# The issue chooser is where a reporter decides how to file. SECURITY.md asks +# that a vulnerability never be a public issue, so the private route has to be +# visible here, next to the public templates, not only in a file the reporter +# may never open. +# +# Blank issues stay enabled: a report that fits neither template is still +# welcome, and this file only adds a route, it does not take one away. + +blank_issues_enabled: true +contact_links: + - name: Report a security vulnerability + url: https://github.com/NHSDigital/software-engineering-quality-framework/security/advisories/new + about: Do not open a public issue. Report it privately here. See SECURITY.md.