Skip to content

Commit 6491193

Browse files
committed
docs: point security policy to canonical website URL
Replace inline SECURITY-POLICY.md with a thin pointer in .github/SECURITY.md to the canonical policy at wolfssl.com/.well-known/vulnerability-disclosure-policy.txt. Keeps PGP key, contact info, and report template reference. Removes SECURITY-POLICY.md (now redundant).
1 parent ac1c727 commit 6491193

2 files changed

Lines changed: 16 additions & 79 deletions

File tree

.github/SECURITY.md

Lines changed: 16 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,23 @@
22

33
## Reporting a Vulnerability
44

5-
**Use of the wolfSSL Vulnerability Report Template is mandatory.** All security reports must use [`SECURITY-REPORT-TEMPLATE.md`](../SECURITY-REPORT-TEMPLATE.md), with every required field completed. Reports that do not use the template, or that leave required fields incomplete, will not receive CVE consideration.
5+
Report security vulnerabilities to **support@wolfssl.com** or call **+1-425-245-8247**.
66

7-
Submit the completed template to **support@wolfssl.com**.
7+
Reports may be encrypted with our PGP key:
88

9-
Non-template submissions may still be reviewed on the merits and, where appropriate, addressed as hardening fixes in a future release.
9+
Fingerprint: A2A4 8E7B CB96 C5BE CB98 7314 EBC8 0E41 5CA2 9677
10+
Key server: keys.openpgp.org
1011

11-
**Please keep the vulnerability private** until a fix has been released.
12+
## Full Policy
1213

13-
For the full policy — severity rubric, coordinated-disclosure practice, and reporter credit — see [`SECURITY-POLICY.md`](../SECURITY-POLICY.md).
14+
Our coordinated vulnerability disclosure policy — including scope, threat-model
15+
boundaries, response commitments, and EU Cyber Resilience Act obligations — is
16+
published at:
17+
18+
https://www.wolfssl.com/.well-known/vulnerability-disclosure-policy.txt
19+
20+
## Report Template
21+
22+
For CVE consideration, submit a completed
23+
[vulnerability report template](../SECURITY-REPORT-TEMPLATE.md) to
24+
**support@wolfssl.com**.

SECURITY-POLICY.md

Lines changed: 0 additions & 74 deletions
This file was deleted.

0 commit comments

Comments
 (0)