diff --git a/.github/SECURITY.md b/.github/SECURITY.md index c2201a628..d024a7f97 100644 --- a/.github/SECURITY.md +++ b/.github/SECURITY.md @@ -15,18 +15,13 @@ If you'd like to be notified of new potential security concerns you can [sign-up If you've found an issue that likely has no impact to existing users (For example, in a development-only branch) feel free to raise it via a standard GitHub bug report issue. -If the issue could have a security impact to BookStack instances, please use one of the below -methods to report the vulnerability: - -- Directly contact the lead maintainer [@ssddanbrown](https://github.com/ssddanbrown). - - You will need to login to be able to see the email address on the [GitHub profile page](https://github.com/ssddanbrown). - - Alternatively you can send a DM via Twitter to [@ssddanbrown](https://twitter.com/ssddanbrown). -- [Disclose via huntr.dev](https://huntr.dev/bounties/disclose) - - Bounties may be available to you through this platform. - - Be sure to use `https://github.com/BookStackApp/BookStack` as the repository URL. +If the issue could have a security impact to BookStack instances, +please directly contact the lead maintainer [@ssddanbrown](https://github.com/ssddanbrown). +You will need to login to be able to see the email address on the [GitHub profile page](https://github.com/ssddanbrown). +Alternatively you can send a DM via Twitter to [@ssddanbrown](https://twitter.com/ssddanbrown). Please be patient while the vulnerability is being reviewed. Deploying the fix to address the vulnerability can often take a little time due to the amount of preparation required, to ensure the vulnerability has been covered, and to create the content required to adequately notify the user-base. -Thank you for keeping BookStack instances safe! \ No newline at end of file +Thank you for keeping BookStack instances safe!