Files

1.3 KiB

Security policy

Reporting a vulnerability

Please do not open a public issue for an undisclosed vulnerability. Contact the snacforge maintainer using one of these private reporting channels:

  • End-to-end encrypted Matrix direct message: @eric:sns.gdn
  • OMEMO-encrypted XMPP message: erici@xmpp.sns.gdn
  • PGP-encrypted email: erici@sdf.org

The PGP public key is available at https://erici.sdf.org/public-key.asc. Verify its fingerprint before use:

4E25 DCA8 A531 6763 A439 1BD2 4AE3 B4BF 07EB EB4F

Include affected versions, reproduction steps, impact, and any suggested mitigation. If none of the private channels are available, open a minimal public issue asking the maintainer to establish a private reporting channel; do not include vulnerability details.

Receipt should be acknowledged within seven days. Status updates are normally provided at least every 14 days until resolution. Reporters are asked to allow 90 days for coordinated disclosure, unless active exploitation or another urgent risk requires a shorter timeline.

Supported versions

Security fixes are provided for the latest snacforge release only. Operators should upgrade to that release before reporting a problem that may already be fixed. Upstream snac vulnerabilities should be reported under upstream's own security policy.