From e2da1f45dfe3e92f09ac6ccfdc1b8b576aa46f43 Mon Sep 17 00:00:00 2001 From: Imani Manyara <19682005+imanimanyara@users.noreply.github.com> Date: Tue, 1 Sep 2026 05:20:08 -0400 Subject: [PATCH 1/2] Route vulnerability disclosure to security@simtabi.com opensource@simtabi.com is the community address; security@simtabi.com is the dedicated disclosure inbox per the org convention, kept separate so a report is never buried in a feature-request thread. --- SECURITY.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/SECURITY.md b/SECURITY.md index 3053662..6dc4e54 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -13,7 +13,7 @@ releases. Older releases receive critical-severity fixes only. **Do not open a public GitHub issue for security problems.** -Disclosure goes to `opensource@simtabi.com`. Include: +Disclosure goes to `security@simtabi.com`. Include: - A description of the vulnerability and its impact. - Steps to reproduce (minimum proof-of-concept). From b52dfbf3a3a5207a10f95d9e8194af1dbd9aa5bb Mon Sep 17 00:00:00 2001 From: Imani Manyara <19682005+imanimanyara@users.noreply.github.com> Date: Mon, 28 Sep 2026 20:47:39 -0400 Subject: [PATCH 2/2] Name private vulnerability reporting; keep design notes out of the repository Private vulnerability reporting is enabled on this repository, so it is the preferred channel, with security@simtabi.com as the fallback. --- SECURITY.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/SECURITY.md b/SECURITY.md index 6dc4e54..6b9011b 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -11,6 +11,8 @@ releases. Older releases receive critical-severity fixes only. ## Reporting a vulnerability +The preferred channel is GitHub private vulnerability reporting: open a private report at . The report stays attached to the repository, with a draft advisory and a CVE request path. Email **security@simtabi.com** if you do not use GitHub. + **Do not open a public GitHub issue for security problems.** Disclosure goes to `security@simtabi.com`. Include: