# Security Advisory - who should I approach?

**URL:** <https://talk.commonmark.org/t/security-advisory-who-should-i-approach/4223>\
**Category:** Spec\
**Created:** [July 5, 2022, 9:03am UTC](https://talk.commonmark.org/t/security-advisory-who-should-i-approach/4223 "2022-07-05T09:03:09Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![tor](https://cdn.commonmark.org/letter_avatar_proxy/v2/letter/t/ecccb3/32.png) [@tor](https://talk.commonmark.org/u/tor)\
**Post date:** [July 5, 2022, 9:03am UTC](https://talk.commonmark.org/t/security-advisory-who-should-i-approach/4223/1 "2022-07-05T09:03:09Z")

</div>

In a case of a security issue, regarding commonmarker with an extension - who should I approach for creating a repository security advisory?
