The security policy for this repository lives at the root, in
SECURITY.md — the canonical location, and the one
GitHub prefers when both exist.
This file is a pointer so that links to .github/SECURITY.md from
older issues, forks, and external references keep resolving. Do not
add policy text here.
- Report a vulnerability privately: https://github.com/sebastienrousseau/dotfiles/security/advisories
- Reporter workflow and encryption:
docs/security/DISCLOSURE.md - Verify a release:
docs/security/VERIFY_RELEASE.md