hygiene: prepare ForgeFlow for public release
Managed validation / full (pull_request) Successful in 27s
Managed validation / full (pull_request) Successful in 27s
This commit is contained in:
+1
-1
@@ -2,7 +2,7 @@
|
||||
|
||||
ForgeFlow's detailed security model is documented in [`docs/SECURITY.md`](docs/SECURITY.md).
|
||||
|
||||
Report suspected vulnerabilities privately to the repository owner. Do not publish Gitea tokens, SSH credentials, update-signing material, private server addresses, support bundles containing sensitive data or other operational secrets in a public issue.
|
||||
Report suspected vulnerabilities privately to `security@itworx.tech`. Do not publish Gitea tokens, SSH credentials, update-signing material, private server addresses, support bundles containing sensitive data or other operational secrets in a public issue.
|
||||
|
||||
For a useful report, include the affected ForgeFlow version/commit, component, minimal reproduction steps, expected and observed behaviour and security impact. Use sanitized or synthetic repository/server data whenever possible.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user