From 5a9052d01fd395ee97e34d0fa2e097f067821ca9 Mon Sep 17 00:00:00 2001 From: Kuba Suder Date: Tue, 22 Sep 2026 03:09:15 +0200 Subject: [PATCH] added SECURITY.md --- SECURITY.md | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..b3fee4b --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,16 @@ +# Security Policy + +## How To Report a Vulnerability + +If you find a potential vulnerability in one of my projects, it's recommended not to report it through a standard publicly-readable issue report, in order to avoid giving possible clues to any potential attackers who could abuse it before it's fixed (see: ["Just a rumour of a bug is enough to find a security exploit these days"](https://anil.recoil.org/notes/rumour-is-the-exploit)). + +You can use one of these to contact me instead: + +- [@mackuba.eu](https://bsky.app/profile/did:plc:oio4hkxaop4ao4wz2pp3f4cr) on Bluesky (my DMs should be open, or mention me discretely with a request for contact) +- [@mackuba@martianbase.net](https://martianbase.net/@mackuba) on Mastodon (my personal instance) +- email: mackuba `@` protonmail.ch (optionally with [this PGP key](https://mail-api.proton.me/pks/lookup?op=get&search=mackuba@protonmail.ch)) +- ["Report a vulnerability"](https://github.com/mackuba/tootify/security/advisories/new) form on GitHub + +I do not check my Twitter/X or LinkedIn accounts regularly. + +Note: please don't submit AI-reported issues that have not been verified manually :) -- 2.51.2