From 03ee4aaa91ed116dcbef83bb0a0291e28e1ec6aa Mon Sep 17 00:00:00 2001 From: Imani Manyara <19682005+imanimanyara@users.noreply.github.com> Date: Tue, 1 Sep 2026 05:20:06 -0400 Subject: [PATCH 1/2] Route vulnerability disclosure to security@simtabi.com opensource@simtabi.com is the community address; security@simtabi.com is the dedicated disclosure inbox per the org convention, kept separate so a report is never buried in a feature-request thread. --- SECURITY.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/SECURITY.md b/SECURITY.md index 4ec66fb..38b0276 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -15,7 +15,7 @@ fixes. Older versions are not patched. See **Do not** open a public GitHub issue for security problems. -Email disclosures to: **`opensource@simtabi.com`** +Email disclosures to: **`security@simtabi.com`** PGP key fingerprint: *to be published in `docs/security.md` ยง Signing*. From d1ba8f44526a9a8516d0a38783b5dd0a299ec529 Mon Sep 17 00:00:00 2001 From: Imani Manyara <19682005+imanimanyara@users.noreply.github.com> Date: Mon, 28 Sep 2026 20:59:08 -0400 Subject: [PATCH 2/2] Name private vulnerability reporting; keep design notes out of the repository Private vulnerability reporting is enabled on this repository, so it is the preferred channel, with security@simtabi.com as the fallback. --- SECURITY.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/SECURITY.md b/SECURITY.md index 38b0276..cbfcd2f 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -13,6 +13,8 @@ fixes. Older versions are not patched. See ## Reporting a vulnerability +The preferred channel is GitHub private vulnerability reporting: open a private report at . The report stays attached to the repository, with a draft advisory and a CVE request path. Email **security@simtabi.com** if you do not use GitHub. + **Do not** open a public GitHub issue for security problems. Email disclosures to: **`security@simtabi.com`**