Skip to content

Commit 0913436

Browse files
authored
Merge pull request #10559 from MarkAtwood/security-policy-canonical-pointer
docs: consolidate security policy to canonical website URL
2 parents 3538c4d + 66fe117 commit 0913436

1 file changed

Lines changed: 18 additions & 4 deletions

File tree

.github/SECURITY.md

Lines changed: 18 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,26 @@
22

33
## Reporting a Vulnerability
44

5-
**Use of the wolfSSL Vulnerability Report Template is mandatory.** All security reports must use [`SECURITY-REPORT-TEMPLATE.md`](../SECURITY-REPORT-TEMPLATE.md), with every required field completed. Reports that do not use the template, or that leave required fields incomplete, will not receive CVE consideration.
5+
**Use of the wolfSSL Vulnerability Report Template is mandatory.** All security
6+
reports must use [`SECURITY-REPORT-TEMPLATE.md`](../SECURITY-REPORT-TEMPLATE.md),
7+
with every required field completed. Reports that do not use the template, or
8+
that leave required fields incomplete, will not receive CVE consideration.
69

7-
Submit the completed template to **support@wolfssl.com**.
10+
Submit the completed template to **support@wolfssl.com**. You may also send it to
11+
**secure@wolfssl.com** and encrypt it with our PGP key:
812

9-
Non-template submissions may still be reviewed on the merits and, where appropriate, addressed as hardening fixes in a future release.
13+
Fingerprint: A2A4 8E7B CB96 C5BE CB98 7314 EBC8 0E41 5CA2 9677
14+
Key server: keys.openpgp.org
15+
16+
Non-template submissions may still be reviewed on the merits and, where
17+
appropriate, addressed as hardening fixes in a future release.
1018

1119
**Please keep the vulnerability private** until a fix has been released.
1220

13-
For the full policy — severity rubric, coordinated-disclosure practice, and reporter credit — see [`SECURITY-POLICY.md`](../SECURITY-POLICY.md).
21+
## Full Policy
22+
23+
For the full policy — severity rubric, scope, coordinated-disclosure practice,
24+
and reporter credit — see [`SECURITY-POLICY.md`](../SECURITY-POLICY.md). The same
25+
policy is also published at
26+
<https://www.wolfssl.com/.well-known/vulnerability-disclosure-policy.txt> so that
27+
other wolfSSL repositories can reference one canonical copy.

0 commit comments

Comments
 (0)