Files

33 lines
1.3 KiB
Markdown

# Security policy
## Reporting a vulnerability
Please do not open a public issue for an undisclosed vulnerability. Contact the
snacforge maintainer using one of these private reporting channels:
- End-to-end encrypted Matrix direct message: `@eric:sns.gdn`
- OMEMO-encrypted XMPP message: `erici@xmpp.sns.gdn`
- PGP-encrypted email: `erici@sdf.org`
The PGP public key is available at
https://erici.sdf.org/public-key.asc. Verify its fingerprint before use:
`4E25 DCA8 A531 6763 A439 1BD2 4AE3 B4BF 07EB EB4F`
Include affected versions, reproduction steps, impact, and any suggested
mitigation. If none of the private channels are available, open a minimal
public issue asking the maintainer to establish a private reporting channel;
do not include vulnerability details.
Receipt should be acknowledged within seven days. Status updates are normally
provided at least every 14 days until resolution. Reporters are asked to allow
90 days for coordinated disclosure, unless active exploitation or another
urgent risk requires a shorter timeline.
## Supported versions
Security fixes are provided for the latest snacforge release only. Operators
should upgrade to that release before reporting a problem that may already be
fixed. Upstream snac vulnerabilities should be reported under upstream's own
security policy.