From 266a74bab887a0b1b86f99c6577321a5d8ad3ef7 Mon Sep 17 00:00:00 2001 From: hank Date: Sun, 6 Sep 2026 10:16:40 -0400 Subject: [PATCH] Update security policy for vulnerability reporting --- SECURITY.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 396ff862..9d665fab 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -2,6 +2,8 @@ ## Reporting a Vulnerability -If you find a vulnerability in the latest version, please [submit a private advisory](https://github.com/henrygd/beszel/security/advisories/new). +**PLEASE ONLY USE SECURITY ADVISORIES FOR REAL HIGH SEVERITY VULNERABILITIES.** -If it's low severity (use best judgement) you may open an issue instead of an advisory. +If you find a vulnerability in the latest version, and it is not high severity, open an issue instead of an advisory. + +I am overwhelmed with advisories, often erroneous, which are clearly found and written by AI. I don't have the capacity to review all of them.