diff --git a/.github/ISSUE_TEMPLATE/SecurityDisclosure.md b/.github/ISSUE_TEMPLATE/SecurityDisclosure.md deleted file mode 100644 index 5429941268..0000000000 --- a/.github/ISSUE_TEMPLATE/SecurityDisclosure.md +++ /dev/null @@ -1,8 +0,0 @@ ---- -name: Security Disclosure / Report -about: Found a security issue? ---- - -STOP RIGHT HERE - DO NOT CREATE A TICKET FOR A SECURITY FINDING IN THE OPEN (HERE OR IN ANY COMMUNITY) - -Security reports should never start out in the open. Please follow up directly with the team if you have a contact. If not you can always start with the information at https://chocolatey.org/security to see instructions on how to provide the disclosure. Thank you! diff --git a/.github/SECURITY.md b/.github/SECURITY.md new file mode 100644 index 0000000000..fc8bb5354b --- /dev/null +++ b/.github/SECURITY.md @@ -0,0 +1,6 @@ +# Security Policies and Procedures + +Security reports should never start out in the open. Please follow up directly +with the team if you have a contact. If not you can always start with the +information at https://chocolatey.org/security to see instructions on how to +provide the disclosure. Thank you!