Skip to content

docs(security): no bounty; report via public GitHub issues only - #83

Merged
paulgnz merged 1 commit into
mainfrom
docs/security-no-bounty-issues-only
Sep 24, 2026
Merged

paulgnz merged 1 commit into
mainfrom
docs/security-no-bounty-issues-only

Conversation

@paulgnz

@paulgnz paulgnz commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

The bounty tiers from #81 brought in a flood of low-quality, automated submissions. This PR:

  • states plainly that there is no bug bounty
  • removes the email channel, so reports go through public GitHub issues only
  • adds a security issue form that requires the component, commit hash and reproduction steps
  • updates the audit addendum to match

Private vulnerability reporting also needs turning off in repo settings. That takes admin rights.

The bounty tiers published in #81 drew a flood of low-quality, automated submissions.
Withdraw the bounty entirely, drop the email channel, and accept reports only as
GitHub issues. Adds a security issue form requiring component, commit hash and
reproduction steps, with 'checked against main' and 'no bounty' acknowledgements.
@paulgnz
paulgnz merged commit b4a1494 into main Sep 24, 2026
7 checks passed
@paulgnz
paulgnz deleted the docs/security-no-bounty-issues-only branch September 24, 2026 19:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant