diff --git a/SECURITY.md b/SECURITY.md index bfa88da1..e793af83 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -14,11 +14,20 @@ requests, or discussions.** Use one of the private channels below: ****, or from this repository's **Security** tab → **Report a vulnerability**. This opens a private advisory visible only to you and the maintainer. -2. **Web form.** If you cannot use GitHub, submit the form at - ****. It routes to a private inbox. +2. **Email.** Write to ****. Use this if you have + something to attach — a proof of concept, a crash dump, a packet capture, a + patch — which the web form cannot take. +3. **Web form.** Submit the form at + ****. It routes to a private inbox, and + needs neither a GitHub account nor a working mail client. -We do not publish a security email address. Both channels above reach the -maintainer privately. +**Email is not encrypted in transit beyond what our providers negotiate.** For +anything you need protected, use GitHub private vulnerability reporting: it is +the reason that channel is listed first. We do not currently publish a PGP key, +and would rather say so than leave you guessing — if you need material encrypted +in transit, that is the channel to use. + +All three routes reach the maintainer privately. ### What to include @@ -27,7 +36,8 @@ The more of this you can provide, the faster we can triage: - Affected component — **Core**, **Platform**, or **Bdd** (see *Scope* below) - Affected version, tag, or commit SHA - A description of the issue and its impact -- Reproduction steps or a proof of concept +- Reproduction steps or a proof of concept (attach it if you are writing by + email) - Your assessment of severity, and whether it is being actively exploited - Whether you wish to be credited, and how diff --git a/docs/release-process.md b/docs/release-process.md index 47909461..addcda3c 100644 --- a/docs/release-process.md +++ b/docs/release-process.md @@ -153,5 +153,9 @@ Coordinated with the disclosure; see the runbook's *Release coordination* stage: hash, and both cosign signatures per [`security/release-verification.md`](security/release-verification.md), not just that the assets are present — a bundle that is present is not yet a - bundle that verifies. + bundle that verifies. Install the tool versions that page states rather + than using whatever is already on your `$PATH`: verifying with your own + toolchain proves the signature good but hides any drift between the guide + and what the workflow actually produces, which is the failure an + integrator meets first. - [ ] Security release: publish the coordinated GHSA. diff --git a/overrides/partials/copyright.html b/overrides/partials/copyright.html index c5a1cb3b..f8799383 100644 --- a/overrides/partials/copyright.html +++ b/overrides/partials/copyright.html @@ -8,9 +8,12 @@ under the same brand as cososo.co.uk, so it carries the same disclosure as that site's footer. The registered name, company number and registered office are as recorded at Companies House for 09856828; the VAT number comes from - HMRC, which Companies House does not hold, so it is verified separately. All - of them are legal particulars, not house style, so do not reflow, abbreviate - or re-punctuate them. + HMRC, which Companies House does not hold, so it is verified separately. The + email address is the contact particular required by regulation 6(1)(c) of the + Electronic Commerce Regulations, and is the general contact address; the + address for reporting vulnerabilities is in SECURITY.md and is deliberately a + different one. All of them are legal particulars, not house style, so do not + reflow, abbreviate or re-punctuate them. The year is taken from build_date_utc rather than written as a literal, so it cannot go stale between releases. @@ -30,6 +33,7 @@