Update security reporting instructions in SECURITY.md

Clarify reporting guidelines for security issues.
This commit is contained in:
Louis Lam 2025-11-16 20:45:49 +08:00 committed by GitHub
parent dda1a3f442
commit f183b75a07
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -8,7 +8,8 @@
do not send a notification, I probably will miss it without this.
<https://github.com/louislam/uptime-kuma/issues/new?assignees=&labels=help&template=security.md>
Do not use the public issue tracker or discuss it in public as it will cause
- Do not report any upstream dependency issues / scan result by any tools. It will be closed immediately without explainations. Unless you have PoC to prove that the upstream issue affected Uptime Kuma.
- Do not use the public issue tracker or discuss it in public as it will cause
more damage.
## Do you accept other 3rd-party bug bounty platforms?