KEMBAR78
docs: update Security section to direct disclosures by aaronbrown-vercel · Pull Request #84156 · vercel/next.js · GitHub
Skip to content

Conversation

@aaronbrown-vercel
Copy link
Contributor

This PR updates the README.md Security section:

  • Removes reference to GitHub’s private vulnerability reporting feature.
  • Directs researchers to email responsible.disclosure@vercel.com.
  • Clarifies that researchers will be added to our Open Source Software Bug Bounty program upon contacting us.

This change aligns our security disclosure process with Vercel’s current bug bounty program enrollment flow.

@ijjk
Copy link
Member

ijjk commented Sep 23, 2025

Allow CI Workflow Run

  • approve CI run for commit: 1fb12d4

Note: this should only be enabled once the PR is ready to go and can only be enabled by a maintainer

1 similar comment
@ijjk
Copy link
Member

ijjk commented Sep 23, 2025

Allow CI Workflow Run

  • approve CI run for commit: 1fb12d4

Note: this should only be enabled once the PR is ready to go and can only be enabled by a maintainer

@ztanner ztanner merged commit f46e17a into canary Sep 23, 2025
120 of 123 checks passed
@ztanner ztanner deleted the abrown/update-vuln-disclosure-path branch September 23, 2025 23:30
@github-actions github-actions bot added the locked label Oct 8, 2025
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Oct 8, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants