From 81a7a6fc4ba44e0bd95af495307d52200033f3c9 Mon Sep 17 00:00:00 2001 From: Dhi13man Date: Tue, 28 Jul 2026 22:36:48 +0530 Subject: [PATCH] docs: link private security reporting Direct vulnerability reporters to the enabled private advisory form so the secure channel is explicit and machine-discoverable. Co-Authored-By: Dhiman's Agentic Suite --- SECURITY.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index fcd4902..a9889a4 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -14,8 +14,8 @@ versions when practical. Do not open a public issue for security-sensitive reports. -Use GitHub private vulnerability reporting if it is enabled for the repository. -If it is not enabled, contact the maintainer privately through the GitHub +Use [GitHub private vulnerability reporting](https://github.com/Dhi13man/avsync/security/advisories/new). +If it is unavailable, contact the maintainer privately through the GitHub repository owner profile and include: - Affected version, commit, or hosted URL.