Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add SECURITY.md #264

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 31 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# Security Policy

## Supported Versions

NLnet Labs adheres to the straightforward, semantic versioning scheme that is
commonly used in the software industry.
Comment on lines +5 to +6
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we want to do this properly, we should probably set up cargo-semver-checks at some point.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If you could have a look at this at some point for other projects such as Routinator and Krill, that would be nice.


Support is provided in respect of the latest release, i.e. releases with the
highest minor and patch version level. We do not backport security fixes to
older (minor) versions. In the event a new major version is released (e.g. from
3.2.18 to 4.0.0), support will also be provided on the latest minor version of
the previous major version (3.2.18) for a period of one year from the release of
the new major version (4.0.0).
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
the new major version (4.0.0).
the new major version (4.0.0), unless the previous major version number was 0 (the 'initial development phase').


In the event that, during this period, a new patch or minor version of the
previous major version is released, then support on these versions will only be
provided for the remainder of the one-year-period.

You can find detailed information on our software support policy here:

https://www.nlnetlabs.nl/support/software-support-policy/

## Reporting a Vulnerability

We take security very seriously. If you have discovered a security vulnerability
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
We take security very seriously. If you have discovered a security vulnerability
If you have discovered a security vulnerability

in one of our projects and you would like to report it to us, you can send an
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
in one of our projects and you would like to report it to us, you can send an
in one of our projects and you would like to report it to us, please send an

encrypted message to our Security Entry Point.

Details are described here:

https://www.nlnetlabs.nl/security-report/
Loading