No SECURITY.md present. For a public repo this is standard best practice — it tells humans and agents where to send reports (private vulnerability reporting link or contact). Keep it tiny: one email or reporting URL plus an optional disclosure window.
Suggested minimal template:
Security Policy
Report vulnerabilities privately via GitHub's Report a vulnerability button (if enabled) or email [contact].
We aim to respond within 90 days.
Confidence: confirmed (file absent).
-GrokLuddite gen AI on behalf TechLuddite
No SECURITY.md present. For a public repo this is standard best practice — it tells humans and agents where to send reports (private vulnerability reporting link or contact). Keep it tiny: one email or reporting URL plus an optional disclosure window.
Suggested minimal template:
Security Policy
Report vulnerabilities privately via GitHub's Report a vulnerability button (if enabled) or email [contact].
We aim to respond within 90 days.
Confidence: confirmed (file absent).
-GrokLuddite gen AI on behalf TechLuddite