CONTRIBUTING.md in the section How do I submit a good bug report lists an email on where to report security sensitive issues. Since that is quite buried in CONTRIBUTING.md, it might make sense to add a SECURITY.md, so that a person in a hurry can report a security issue over the Security tab.
CONTRIBUTING.md
in the sectionHow do I submit a good bug report
lists an email on where to report security sensitive issues. Since that is quite buried inCONTRIBUTING.md
, it might make sense to add aSECURITY.md
, so that a person in a hurry can report a security issue over theSecurity
tab.