Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove note that is contradicted in the subsequent paragraph #33268

Closed
wants to merge 2 commits into from

Conversation

jmandel
Copy link

@jmandel jmandel commented May 31, 2024

Why: remove contradictory information

Closes:

What's being changed (if available, include any code snippets, screenshots, or gifs):

Remove a note stating that security reports cannot be made to repositories that do not opt into receiving them

Check off the following:

  • I have reviewed my changes in staging, available via the View deployment link in this PR's timeline (this link will be available after opening the PR).

    • For content changes, you will also see an automatically generated comment with links directly to pages you've modified. The comment won't appear if your PR only edits files in the data directory.
  • For content changes, I have completed the self-review checklist.


The paragraph following the deleted line says that reports can be made to public repositories even if they have not turned on this feature.

Copy link

welcome bot commented May 31, 2024

Thanks for opening this pull request! A GitHub docs team member should be by to give feedback soon. In the meantime, please check out the contributing guidelines.

@github-actions github-actions bot added the triage Do not begin working on this issue until triaged by the team label May 31, 2024
Copy link
Contributor

github-actions bot commented May 31, 2024

Automatically generated comment ℹ️

This comment is automatically generated and will be overwritten every time changes are committed to this branch.

The table contains an overview of files in the content directory that have been changed in this pull request. It's provided to make it easy to review your changes on the staging site. Please note that changes to the data directory will not show up in this table.


Content directory changes

You may find it useful to copy this table into the pull request summary. There you can edit it to share links to important articles or changes and to give a high-level overview of how the changes in your pull request support the overall goals of the pull request.

Source Preview Production What Changed
code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability.md fpt
ghec
fpt
ghec

fpt: Free, Pro, Team
ghec: GitHub Enterprise Cloud
ghes: GitHub Enterprise Server

@nguyenalex836 nguyenalex836 added content This issue or pull request belongs to the Docs Content team waiting for review Issue/PR is waiting for a writer's review code security Content related to code security and removed triage Do not begin working on this issue until triaged by the team labels May 31, 2024
@nguyenalex836
Copy link
Contributor

@jmandel Thanks so much for opening a PR! I'll get this triaged for review ✨

enyart1

This comment was marked as spam.

@mchammer01 mchammer01 self-requested a review June 3, 2024 09:56
@mchammer01
Copy link
Contributor

Thanks for your contribution @jmandel
We will review this PR this week!

@2chiefk

This comment was marked as spam.

@mchammer01
Copy link
Contributor

@jmandel -I am not sure that there is a contradiction between both the note and the paragraph, but I agree that you've highlighted confusing content, that we should improve on. Thanks you so much for that 💖 ✨
We will fix this internally as I need to discuss with the team in charge how they'd like to proceed with this.
As a result, I will close this issue.

@mchammer01 mchammer01 closed this Jun 7, 2024
@jmandel
Copy link
Author

jmandel commented Jun 7, 2024

Thanks! It sounds like I misunderstood the content. Here are some suggestions for how to make it clearer, @mchammer01.

If you do not have admin or security permissions for a public repository, you can still privately report a security vulnerability

If I understand correctly, this could be rewritten more clearly as something like

If a public repository has enabled "Private vulnerability reporting," anyone can report an issue by clicking "Security" ...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
code security Content related to code security content This issue or pull request belongs to the Docs Content team waiting for review Issue/PR is waiting for a writer's review
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants