From 6da95b44eaede70bce552da3d011f6e06631e047 Mon Sep 17 00:00:00 2001 From: Eric Ireland Date: Fri, 11 Sep 2026 14:07:22 +1000 Subject: [PATCH] Add encrypted security reporting channels --- SECURITY.md | 20 +++++++++++++++----- 1 file changed, 15 insertions(+), 5 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 2c542f7..2b2ac32 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -3,11 +3,21 @@ ## Reporting a vulnerability Please do not open a public issue for an undisclosed vulnerability. Contact the -snacforge maintainer in an end-to-end encrypted Matrix direct message at -`@eric:sns.gdn`. Include affected versions, reproduction steps, impact, and any -suggested mitigation. If Matrix is unavailable, open a minimal public issue -asking the maintainer to establish a private reporting channel; do not include -vulnerability details. +snacforge maintainer using one of these private reporting channels: + +- End-to-end encrypted Matrix direct message: `@eric:sns.gdn` +- OMEMO-encrypted XMPP message: `erici@xmpp.sns.gdn` +- PGP-encrypted email: `erici@sdf.org` + +The PGP public key is available at +https://erici.sdf.org/public-key.asc. Verify its fingerprint before use: + +`4E25 DCA8 A531 6763 A439 1BD2 4AE3 B4BF 07EB EB4F` + +Include affected versions, reproduction steps, impact, and any suggested +mitigation. If none of the private channels are available, open a minimal +public issue asking the maintainer to establish a private reporting channel; +do not include vulnerability details. Receipt should be acknowledged within seven days. Status updates are normally provided at least every 14 days until resolution. Reporters are asked to allow