update security.md, security doc to point to GitHub vulnerability reporting

This commit is contained in:
Min RK
2025-05-31 09:18:10 +02:00
parent bc21e99e7e
commit 2babc7ae83
2 changed files with 7 additions and 3 deletions

View File

@@ -5,7 +5,11 @@
If you find a security vulnerability in Jupyter or JupyterHub,
whether it is a failure of the security model described in [Security Overview](explanation:security)
or a failure in implementation,
please report it to <mailto:security@ipython.org>.
please report it!
Please use GitHub's "Report a Vulnerability" button under Security > Advisories on the appropriate repo,
e.g. [report here for JupyterHub](https://github.com/jupyterhub/jupyterhub/security/advisories).
You may also send an email to <mailto:security@ipython.org>, but the GitHub reporting system is preferred.
If you prefer to encrypt your security reports,
you can use {download}`this PGP public key </ipython_security.asc>`.