The dbus maintainers can open confidential merge requests by using a
private git repository, but other contributors (including most security
researchers) cannot, so the safest simple recommendation is no merge
requests.
Signed-off-by: Simon McVittie <smcv@collabora.com>
or by reporting a Gitlab issue at
https://gitlab.freedesktop.org/dbus/dbus/issues/new and marking it
as "confidential".
+Please do not open merge requests for security issues: if you have a
+proposed patch, it can be discussed on the confidential issue or by
+private email.
On Unix systems, the system bus (dbus-daemon --system) is designed
to be a security boundary between users with different privileges.