diff options
author | Phil Pennock <pdp@exim.org> | 2019-06-19 15:37:19 -0400 |
---|---|---|
committer | Phil Pennock <pdp@exim.org> | 2019-06-19 15:37:19 -0400 |
commit | 3ff0668bf4565e7f8ea4b843474ddb49cce46fed (patch) | |
tree | b4977f1c849fe0e4d23d187d96a53aba2a3bee2c /SECURITY.md | |
parent | e59797e3bda39abf611063fc0ba38fcb4e6596e4 (diff) |
Add a security page in a place where GitHub will detect it
Diffstat (limited to 'SECURITY.md')
-rw-r--r-- | SECURITY.md | 30 |
1 files changed, 30 insertions, 0 deletions
diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 000000000..5580a8cfc --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,30 @@ +# Security Policy + +## Supported Versions + +We are an open source project with no corporate sponsor and no formal +"support". In practice, we support the latest released version and work with +OS vendors to make it easy for them to backport fixes for their distributed +packages. For some security issues, we will issue a patch-release which has +just a simple fix. + +We also often have `exim_VERSION+fixes` branches with small things which we +recommend that vendors use. + +For postmasters installing Exim manually, we recommend always using the latest +released tarball. + +## Reporting a Vulnerability + +Our security page is at <https://wiki.exim.org/EximSecurity>. +It contains the current contact point and list of PGP keys to use for +encrypting particularly sensitive information. +This also links to our documentation and the chapter on security +considerations. + +Our security release process is at +<https://wiki.exim.org/SecurityReleaseProcess>. +This covers what we do in handling vulnerability reports. + +We have no bug bounty program of our own; we're far too disparate a group of +volunteers for such things. |