docs: link the contributing guide straight at the security policy - #19
Conversation
The link pointed at cosmos/security/SECURITY.md, which has been a pointer back to this file since #15. Contributors were sent to another repository to be sent back here. The policy lives in this repo, so link it relatively.
|
| Never open a public issue, pull request, or discussion for a suspected | ||
| vulnerability. Report it through the | ||
| [security policy](https://github.com/cosmos/security/blob/main/SECURITY.md) | ||
| [security policy](SECURITY.md) |
There was a problem hiding this comment.
Policy link may break If a Cosmos repository displays this organization-wide guide but has no
SECURITY.md of its own, the relative link can resolve against that repository. Contributors would then reach a missing file instead of the disclosure policy. Link directly to the policy in cosmos/.github so it works from consuming repositories.
This file is an org default community health file, so GitHub serves it from repositories that have no CONTRIBUTING of their own. A relative SECURITY.md resolves against the consuming repository, and cosmos/evm, cosmos/cosmos-sdk and cosmos/ibc-go have no SECURITY.md of their own, so the link would have 404'd for exactly the repositories this file exists to serve. Absolute to cosmos/.github still removes the round trip through cosmos/security, which was the point of the change.
CONTRIBUTING.mdlinkedcosmos/security/SECURITY.md, which points straight back here. Now a relative link.Leave that pointer file alone, 11 other links still depend on it.