From 7e617a632eef9ff6df92851cce8e2224a7146fd4 Mon Sep 17 00:00:00 2001 From: Andy Miller Date: Tue, 22 Aug 2023 09:24:41 +0100 Subject: [PATCH] updated security.md --- SECURITY.md | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/SECURITY.md b/SECURITY.md index 30830c784..ffe8f7902 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -18,4 +18,12 @@ If you cannot update to the latest stable version available because, for example ## Reporting a Vulnerability -Please contact security@getgrav.org with a detailed explaination of the security issue found and we will work with you to get it resolved as fast as possible. +Please contact security@getgrav.org with a detailed explanation of the security issue found. If it appears to be a legitimate issues, please submit an **advisory via GitHub Security**: https://github.com/getgrav/grav/security/advisories + +>> NOTE: Please do not use 3rd party security issue reporting services, we like to keep everything in the GitHub ecosystem for easier manageability. + +## Bug Bounties + +We do greatly appreciate your efforts to improve Grav, but unfortunately because we are a small open source project, we **do not have the resources to offer bounties** for security issues found. + +