33 lines
1.3 KiB
Markdown
33 lines
1.3 KiB
Markdown
# Security policy
|
|
|
|
## Reporting a vulnerability
|
|
|
|
Please do not open a public issue for an undisclosed vulnerability. Contact the
|
|
snacforge maintainer using one of these private reporting channels:
|
|
|
|
- End-to-end encrypted Matrix direct message: `@eric:sns.gdn`
|
|
- OMEMO-encrypted XMPP message: `erici@xmpp.sns.gdn`
|
|
- PGP-encrypted email: `erici@sdf.org`
|
|
|
|
The PGP public key is available at
|
|
https://erici.sdf.org/public-key.asc. Verify its fingerprint before use:
|
|
|
|
`4E25 DCA8 A531 6763 A439 1BD2 4AE3 B4BF 07EB EB4F`
|
|
|
|
Include affected versions, reproduction steps, impact, and any suggested
|
|
mitigation. If none of the private channels are available, open a minimal
|
|
public issue asking the maintainer to establish a private reporting channel;
|
|
do not include vulnerability details.
|
|
|
|
Receipt should be acknowledged within seven days. Status updates are normally
|
|
provided at least every 14 days until resolution. Reporters are asked to allow
|
|
90 days for coordinated disclosure, unless active exploitation or another
|
|
urgent risk requires a shorter timeline.
|
|
|
|
## Supported versions
|
|
|
|
Security fixes are provided for the latest snacforge release only. Operators
|
|
should upgrade to that release before reporting a problem that may already be
|
|
fixed. Upstream snac vulnerabilities should be reported under upstream's own
|
|
security policy.
|