gittuf/SECURITY.md
Aditya Sirish f929cef429
Add security response process
Signed-off-by: Aditya Sirish <aditya@saky.in>
2023-08-31 11:38:42 -04:00

20 lines
914 B
Markdown

# Reporting Security Issues
Please report security issues **confidentially** using
[GitHub's form](https://github.com/gittuf/gittuf/security/advisories/new).
Alternatively, you can send an encrypted email to `jcappos@nyu.edu` using the
following PGP key:
> E9C0 59EC 0D32 64FA B35F 94AD 465B F9F6 F8EB 475A
**Note:** Please do not report such issues publicly on the issue tracker. The
*issue tracker is intended for bug reports and feature requests.
## Responding to Reports
A gittuf maintainer will respond to the report as soon as possible. After the
report is triaged and the vulnerability is confirmed, a fix will be prepared
under embargo. Once the fix is accepted, a new release will be prepared along
with a report detailing the vulnerability. This report will identify the
reporter unless they request to be kept anonymous. Finally, a CVE may be
requested if appropriate for the vulnerability report.