Update vulnerability reporting instructions in SECURITY.md (#25651)

Update instructions from email to GitHub report
This commit is contained in:
Nick Acosta 2026-01-30 14:03:09 -08:00 committed by GitHub
parent 1b295fb632
commit 54b2d022b9
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -14,8 +14,8 @@ currently being supported with security updates.
Reporting security issues
If you think you have found a security vulnerability, please send a report to security@open-metadata.org. This address can be used for all of OpenMetadata products.
If you think you have found a security vulnerability, please create a GitHub Security Advisory [here](https://github.com/open-metadata/OpenMetadata/security/advisories/new). This can be used for all of OpenMetadata products.
OpenMetadata will send you a response indicating the next steps in handling your report. After the initial reply to your report, the OpenMetadata team will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.
The security advisory should be open in a draft mode. After the initial reply to your report, the OpenMetadata team will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.
Important: We ask you to not disclose the vulnerability before it have been fixed and announced, unless you received a response from the OpenMetadata team that you can do so.