Skip to content

Commit

Permalink
Use Signal instead of PGP to contact me securely (#52)
Browse files Browse the repository at this point in the history
  • Loading branch information
djmitche authored Nov 16, 2024
1 parent 4727c9b commit 7d0325e
Showing 1 changed file with 13 additions and 0 deletions.
13 changes: 13 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# Security

To report a vulnerability, please contact Dustin via signal, [`djmitche.78`](https://signal.me/#eu/2T98jpkMAzvFL2wg3OkZnNrfhk1DFfu6eqkMEPqcAuCsLZPVk39A67rp4khmrMNF).
Initial response is expected within ~48h.

We kindly ask to follow the responsible disclosure model and refrain from sharing information until:

1. Vulnerabilities are patched in `taskchampion-sync-server` + 60 days to coordinate with distributions.
2. 90 days since the vulnerability is disclosed to us.

We recognise the legitimacy of public interest and accept that security researchers can publish information after 90-days deadline unilaterally.

We will assist with obtaining CVE and acknowledge the vulnerabilities reported.

0 comments on commit 7d0325e

Please sign in to comment.