Update SECURITY.md vulnerability reporting instructions (#15089)

Made-with: Cursor

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Documentation-only change; no code or runtime behavior is affected,
but it changes the official intake channels for vulnerability reports.
> 
> **Overview**
> Updates `SECURITY.md` to redirect vulnerability reporters from
emailing the core team to using the **Redis Vulnerability Disclosure
Program** link, with GitHub’s *Report a Vulnerability* as an
alternative.
> 
> Adds a dedicated security contact email (`security@redis.com`) for
questions and includes brief rationale for the new reporting path.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
eeaa8c4ada3152c7dc37f6338f3d6f9c178dfdb9. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
This commit is contained in:
Curtis Means
2026-04-27 19:03:31 +03:00
committed by GitHub
parent 77628f370a
commit 861917603e
+14 -4
View File
@@ -23,10 +23,20 @@ unless this is not possible or feasible with a reasonable effort.
## Reporting a Vulnerability
If you believe you've discovered a serious vulnerability, please contact the
Redis core team at redis@redis.io. We will evaluate your report and if
necessary issue a fix and an advisory. If the issue was previously undisclosed,
we'll also mention your name in the credits.
If you believe you have found a security vulnerability, to ensure proper review
and assessment, we kindly ask vulnerability reports be submitted through
our [Redis Vulnerability Disclosure Program.](https://redis.io/redis-responsible-vulnerability-disclosure/)
We have found this path to be beneficial for both researchers and us for
a number of reasons. Including, offering fast response times to researchers and
opportunities for us to invite those with exceptional reports into closed paid
engagements.
For those averse to using our chosen platform, we will also accept reports directly
via GitHub's "Report a Vulnerability".
To contact the security team directly with questions use: [security@redis.com](mailto:security@redis.com)
## Responsible Disclosure