Skip to content

docs: offer private vulnerability reporting in the issue chooser - #85

Merged
Foxlider merged 1 commit into
Foxlider:developfrom
MrBeldum:feature/security-contact-link
Oct 5, 2026
Merged

Foxlider merged 1 commit into
Foxlider:developfrom
MrBeldum:feature/security-contact-link

Conversation

@MrBeldum

@MrBeldum MrBeldum commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Summary

SECURITY.md says not to report vulnerabilities through public issues and points to private vulnerability reporting as the preferred route. The issue chooser lists the bug/feature templates, Discord, and the contributing guide, but not that form, so a reporter only finds it if they open SECURITY.md first.

This adds a "Report a security vulnerability" contact link to the private advisory form, at the top of the existing contact_links.


Type of Change

  • docs — documentation only

What Changed

  • .github/ISSUE_TEMPLATE/config.yml: add one contact link to https://github.com/Foxlider/KAST/security/advisories/new. The Discord and Contributing Guide links and blank_issues_enabled: false are unchanged.

Private vulnerability reporting is already enabled for this repository (GET /repos/Foxlider/KAST/private-vulnerability-reporting returns {"enabled":true}).


Testing

  • Parsed the file as YAML. It still has the same shape (blank_issues_enabled plus a contact_links list of name/url/about), now with three entries.
  • No application code changed, so dotnet test is not affected.

Checklist

  • PR title follows Conventional Commits format
  • Targets develop from a feature/ branch
  • No unrelated changes mixed in
  • I have read CONTRIBUTING.md

SECURITY.md asks reporters not to use public issues and points them at
the private advisory form, but the issue chooser listed only the public
templates, Discord, and the contributing guide. Add a contact link to the
enabled private vulnerability reporting form so the private route is
visible where a reporter decides how to file.
@Foxlider
Foxlider merged commit 6133a00 into Foxlider:develop Oct 5, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants