|
2 | 2 |
|
3 | 3 | ## Reporting a Vulnerability |
4 | 4 |
|
5 | | -**Use of the wolfSSL Vulnerability Report Template is mandatory.** All security reports must use [`SECURITY-REPORT-TEMPLATE.md`](../SECURITY-REPORT-TEMPLATE.md), with every required field completed. Reports that do not use the template, or that leave required fields incomplete, will not receive CVE consideration. |
| 5 | +**Use of the wolfSSL Vulnerability Report Template is mandatory.** All security |
| 6 | +reports must use [`SECURITY-REPORT-TEMPLATE.md`](../SECURITY-REPORT-TEMPLATE.md), |
| 7 | +with every required field completed. Reports that do not use the template, or |
| 8 | +that leave required fields incomplete, will not receive CVE consideration. |
6 | 9 |
|
7 | | -Submit the completed template to **support@wolfssl.com**. |
| 10 | +Submit the completed template to **support@wolfssl.com**. You may also send it to |
| 11 | +**secure@wolfssl.com** and encrypt it with our PGP key: |
8 | 12 |
|
9 | | -Non-template submissions may still be reviewed on the merits and, where appropriate, addressed as hardening fixes in a future release. |
| 13 | + Fingerprint: A2A4 8E7B CB96 C5BE CB98 7314 EBC8 0E41 5CA2 9677 |
| 14 | + Key server: keys.openpgp.org |
| 15 | + |
| 16 | +Non-template submissions may still be reviewed on the merits and, where |
| 17 | +appropriate, addressed as hardening fixes in a future release. |
10 | 18 |
|
11 | 19 | **Please keep the vulnerability private** until a fix has been released. |
12 | 20 |
|
13 | | -For the full policy — severity rubric, coordinated-disclosure practice, and reporter credit — see [`SECURITY-POLICY.md`](../SECURITY-POLICY.md). |
| 21 | +## Full Policy |
| 22 | + |
| 23 | +For the full policy — severity rubric, scope, coordinated-disclosure practice, |
| 24 | +and reporter credit — see [`SECURITY-POLICY.md`](../SECURITY-POLICY.md). The same |
| 25 | +policy is also published at |
| 26 | +<https://www.wolfssl.com/.well-known/vulnerability-disclosure-policy.txt> so that |
| 27 | +other wolfSSL repositories can reference one canonical copy. |
0 commit comments