Is Reporting Through security@openzeppelin.org the Correct Process?

Hi everyone,

I'm new to smart contract security research.

Recently I reported what I believe is a potential vulnerability to the OpenZeppelin security team via their security email (@openzeppelin.org/security@openzeppelin.com) because I currently don't meet the reputation requirements for the Immunefi program.

I have not disclosed any technical details publicly and will wait for their response.

I just wanted to ask:

  • Is reporting via the security email the correct process?
  • Approximately how long does OpenZeppelin usually take to acknowledge or respond?
  • Is there anything else I should do while waiting?

Thanks!