chore: clarify order of preference for reporting vulnerabilities
Diff
1diff --git a/SECURITY.md b/SECURITY.md
2index ae7458ee20459ee445dd6a31fb6c3c7af6d7358a..f8235840f21600035d004b403e229cd696201c69 100644
3--- a/SECURITY.md
4+++ b/SECURITY.md
5@@ -17,7 +17,7 @@ In the near future we will introduce versioning, so expect this section to chang
6 7 **Do not submit an issue or pull request**: this might reveal the vulnerability.
8 9-Instead, you should email the maintainers directly at: [**security@ohmyz.sh**](mailto:security@ohmyz.sh),
10-or using the link to [privately report a vulnerability with GitHub](https://github.com/ohmyzsh/ohmyzsh/security/advisories/new).
11+Instead, you should use the form to [privately report a vulnerability to us via GitHub](https://github.com/ohmyzsh/ohmyzsh/security/advisories/new)
12+or email the maintainers directly at: [**security@ohmyz.sh**](mailto:security@ohmyz.sh).
1314 We will deal with the vulnerability privately and submit a patch as soon as possible.