Skip to content

Update security reporting instructions in SECURITY.md#6355

Merged
louislam merged 2 commits intomasterfrom
louislam-patch-1
Nov 16, 2025
Merged

Update security reporting instructions in SECURITY.md#6355
louislam merged 2 commits intomasterfrom
louislam-patch-1

Conversation

@louislam
Copy link
Copy Markdown
Owner

Clarify and save time in the future, because I don't want to explain again.

Clarify reporting guidelines for security issues.
Copilot AI review requested due to automatic review settings November 16, 2025 12:47
@louislam
Copy link
Copy Markdown
Owner Author

@copilot Check my grammar

Copy link
Copy Markdown
Contributor

Copilot AI commented Nov 16, 2025

@louislam I've opened a new pull request, #6356, to work on those changes. Once the pull request is ready, I'll request review from you.

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the security reporting instructions in SECURITY.md to clarify what types of security reports should not be submitted, specifically addressing upstream dependency issues.

Key Changes

  • Added a new bullet point clarifying that upstream dependency issues or tool scan results should not be reported without proof of concept (PoC) demonstrating impact on Uptime Kuma

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@louislam louislam merged commit f9751bf into master Nov 16, 2025
6 checks passed
@louislam louislam deleted the louislam-patch-1 branch November 16, 2025 14:40
@CommanderStorm CommanderStorm added this to the 2.1.0 milestone Nov 23, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants