From 6b42643335785469ae188b7927323c475a5366d8 Mon Sep 17 00:00:00 2001 From: wshallwshall Date: Thu, 30 Jul 2026 13:08:49 -0500 Subject: [PATCH] Security policy: replace the dead email fallback with a working channel SECURITY.md offered "email the maintainer at the address on the GitHub profile" as the alternative to a private advisory, but neither the MEFORORG org profile nor the maintainer profile publishes an email, so that route went nowhere. GitHub's private reporting also requires an account, leaving reporters without one with no private path at all. Point them at security@messagefoundry.org instead, noting that plain email isn't end-to-end encrypted so the advisory stays preferred for a detailed report, and that the website contact form is not a channel for vulnerability details. Co-Authored-By: Claude Opus 5 --- .github/SECURITY.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/.github/SECURITY.md b/.github/SECURITY.md index 02bb9da5..572037de 100644 --- a/.github/SECURITY.md +++ b/.github/SECURITY.md @@ -15,7 +15,11 @@ verify a report against current `main` before filing. - **Preferred (always available, fully private):** open a [GitHub private security advisory](https://github.com/MEFORORG/MessageFoundry/security/advisories/new) ("Report a vulnerability") — GitHub keeps it private to the maintainers until coordinated disclosure. This is the recommended channel. -- Alternatively, email the maintainer at the address on the GitHub profile. +- **No GitHub account?** Email **** — it reaches the maintainers + directly. Ordinary email is not end-to-end encrypted, so the advisory above is still preferred for a + detailed report; if you only have email, send a short notice and we will open a private channel. + Please do **not** use the website contact form for vulnerability details — it is routed through a + third-party form service. If you cannot reach a maintainer privately within a few business days, you may request a contact via a **non-detail** public issue (title only, e.g. "requesting a private security contact") — **never** put