Skip to content

Commit ff460e1

Browse files
authored
Update security vulnerability reporting policy (#25)
1 parent e72987c commit ff460e1

1 file changed

Lines changed: 6 additions & 2 deletions

File tree

SECURITY.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -149,6 +149,10 @@ Pi session logs (`.jsonl` files) contain the complete conversation history. If p
149149
| `bin/harden-permissions.sh` | Lock down pi state file permissions | baudbot_agent |
150150
| `bin/setup-firewall.sh` | Apply port-based network restrictions | root |
151151

152-
## Reporting
152+
## Reporting Vulnerabilities
153153

154-
This is a private repo. Report security issues directly to the admin.
154+
Do **not** open a public GitHub issue for security vulnerabilities.
155+
156+
Instead, use [GitHub Security Advisories](https://github.com/modem-dev/baudbot/security/advisories/new) to report privately. You can also email security@modem.dev.
157+
158+
We'll acknowledge reports within 48 hours and aim to release a fix within 7 days for critical issues.

0 commit comments

Comments
 (0)