Skip to content

Commit cc1e59b

Browse files
committed
Update security info
1 parent 52d7a4a commit cc1e59b

File tree

4 files changed

+88
-3
lines changed

4 files changed

+88
-3
lines changed

CONTRIBUTING.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,8 @@ to help and details about how this project handles them. Please make sure to rea
88
your contribution. It will make it a lot easier for us maintainers and smooth out the experience for all involved. The
99
community looks forward to your contributions. 🎉
1010

11+
For security issues, please follow the instructions in the [Security](./SECURITY.md) section.
12+
1113
> And if you like the project, but just don't have time to contribute, that's fine. There are other easy ways to support
1214
> the project and show your appreciation, which we would also be very happy about:
1315
>
@@ -90,7 +92,7 @@ following steps in advance to help us fix any potential bug as fast as possible.
9092
#### How Do I Submit a Good Bug Report?
9193

9294
> You must never report security related issues, vulnerabilities or bugs including sensitive information to the issue
93-
> tracker, or elsewhere in public. Instead sensitive bugs must be sent by email to <dr8co@duck.com>.
95+
> tracker, or elsewhere in public. Check the [Security](./SECURITY.md) section for more information.
9496
9597
We use GitHub issues to track bugs and errors. If you run into an issue with the project:
9698

README.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -458,13 +458,15 @@ sudo rpm -i privacyshield-3.0.0-1.x86_64.rpm # Replace with the actual file path
458458
```
459459

460460
The packages can be verified using the [GnuPG](https://gnupg.org/) signature files provided.
461-
To verify the packages, first import the public key from the releases page:
461+
To verify the packages, first import the [public GPG key](./security/privacyShield_pub_key.asc) provided:
462462

463463
```bash
464464
gpg --import public_gpg_key.asc
465465
```
466466

467-
Then verify the package using the signature file (which can be found on the releases page as well):
467+
The public key is provided in the [releases page](https://github.com/dr8co/PrivacyShield/releases) as well.
468+
Then verify the package using the signature file (which can also be found on the
469+
[releases page](https://github.com/dr8co/PrivacyShield/releases)):
468470

469471
```bash
470472
gpg --verify signatures/privacyshield_3.0.0_amd64.deb.sig privacyshield_3.0.0_amd64.deb

SECURITY.md

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
# Security
2+
3+
We take the security of Privacy Shield seriously.
4+
If you believe you have found a security vulnerability in the source code,
5+
please report it to us as described below.
6+
7+
## Reporting Security Issues
8+
9+
**Please do not report security vulnerabilities through public GitHub issues.**
10+
11+
Instead, please send an encrypted email to [dr8co@duck.com](mailto:dr8co@duck.com).
12+
Encrypt your message with our PGP key; it can be found [here](./security/privacyShield_pub_key.asc).
13+
14+
Please include the requested information listed below (as much as you can provide)
15+
to help us better understand the nature and scope of the possible issue:
16+
17+
* Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
18+
* Full paths of source file(s) related to the manifestation of the issue
19+
* The location of the affected source code (tag/branch/commit or direct URL)
20+
* Any special configuration required to reproduce the issue
21+
* Step-by-step instructions to reproduce the issue
22+
* Proof-of-concept or exploit code (if possible)
23+
* Impact of the issue, including how an attacker might exploit the issue
24+
25+
This information will help us triage your report more quickly.
26+
27+
## Preferred Languages
28+
29+
We prefer all communications to be in English.

security/privacyShield_pub_key.asc

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
-----BEGIN PGP PUBLIC KEY BLOCK-----
2+
3+
mQINBGXUykUBEAD0nkmT6SgkJnlXTx2aEJ23bl87TZR3gW3v+uNQn5ISaUw1WJtE
4+
8XYYkibTBz88W8EeozXGfRn3UDs4g1UOvMcYlfibOxHUZm0MPrueJhFptaBs/x6h
5+
Y0zaODlX3ZpM3ISGu1o4mwLTOhHhP+15XkbT+b7Cbf1HFKplPyp8TS/s0cUfSq5f
6+
Thg8ngIbnkUp4S5cqKJMV3yyK0NyqYE8IJMNOMTot7szFA06phUp5XbOl+Jmhbr2
7+
I3YPWE/guFw0R4IX3klXOITLs5iJFkrLL5VbGseF0YQUkGVFTiTovuc8hcvmbS8x
8+
mU+lH0IkRnye1F9fogymhuiX8vL5Gf9C6gNr0mpWxaHtFAkVqmchhmWWRn3RGkHM
9+
6kdYrEj5yDrhwI8ZPVjh34XDQMg7pXIdiHZbTZMm/RA944VhdfjYs3VS/FZ3Oz9k
10+
Rf5M830x9ifG28dCMiVFhYn5jm4hOmh6KrfPxK7Muf2XFJP6DiBNAT07LDq/DeG8
11+
qk/VALH6vKElFADVsrn2QVq8LmapmYwMl9l2Bmb6isWsuu+RUGft3MvwygUfve5b
12+
9NQYITGGhmD/jH5IXiW/iU+6tIQx9UFaQTm9Plg4LChnVQpMqxp0YhX47QNZFyWB
13+
qJ+N47DTGcjDENQcXTidu4kgV0jf26y2MQ8N0GvufJXvA3NuHpcfJ1e7uwARAQAB
14+
tD9JYW4gRHVuY2FuIChTaWduaW5nIGtleSBmb3IgcGVyc29uYWwgcHJvamVjdHMp
15+
IDxkcjhjb0BkdWNrLmNvbT6JAk4EEwEKADgWIQRkiIHdBB6Z7skF/YG9mRSEoI6b
16+
xQUCZdTKRQIbAwULCQgHAgYVCgkICwIEFgIDAQIeAQIXgAAKCRC9mRSEoI6bxXuU
17+
D/0eYT2v5b8E6Ws8rNh0hzglzC9BiZDG2NWoaz1O26ixXPdzymYFB1xvNFS4UONP
18+
1YDGGfFTBjhsseUwv11N6ZahwzGIkBnMUwH/Vbx2Rt4NTXkukfqeHaTM/jTPZUMn
19+
OzBcECaE9Buph18c05tlXGb60+40R4zB/uTPys5qzuVCs0Us4X5CIt7GHC/hwJiW
20+
hxEZyA/S0ardVyh1dQEpKV6PeWczwvfkqPBymsx5FLABC5N2epPq7OO6Uv/tMOfC
21+
UrM/7z1CEY/vmHcD+fpfsXK4Y4ixaUrs8BJQtmaYrVSH+wHlmlNumudI6VtPU7i1
22+
egTpJ4ViidqzzZLL075hGCEczsp3EqtBKpik+ZpHXHSpMYeuLvqz20PAP3jAYNHV
23+
k7vcv39mDsivf//GbfObQ43kKpWvfJ6lwb4EaopL8RLCFxGDrLM2bf1cb/WRULBw
24+
YAgiF7gfYpe4rPUlp1/xFkdH5lBZay1sFN8rVu0wPwung7czQHypNo0jYrvHiufD
25+
BDkr0sQznV6dKBY8uhMhkhiVhq2hast6I5rNkJSRx6ZpIROYVF5xnlAGaJ/C9SKK
26+
zInHVJRWW19RNDfVj9Ld9O6fgsnGTOiJDSmH1J6jbdNoqafNc1EyXnYT0Dl5rQ0f
27+
HDZMYssMgdIGIjh4gtNAuW/T8vE0rXl33+vwSvV7aJf1NLkCDQRl1MpFARAAv2hF
28+
AbLa0Q7YUQXVma6Dr72ML8bdF1q1xXC1vD+L7Aka+TFjzHmgeQxmDsP9LvAAkRAg
29+
K7XKLYJqT7nvHfr8g8flUiSImBRXHV7OBlVXiVmVJqKSMoFC6TOvGyrvlESDlBAB
30+
SZayNTihRZz/fIdiahZ+Iblwp3/9ZwufAqPsYlgfL51SLUZZnohw2jzDbNTToVsk
31+
W6qQKvjbDYOJk+/i4jNnmnoN3T39zRUqKiKudNHtspha424eRys6sBgTni4mSZ2b
32+
8FpWmC+ou7Ichkb4i0RU1sS+LgnwzP9yic9qEQDzhLcBqcFiSWJV1gwyzE+gbc3i
33+
KGAfXV6cIHpjA5ZrSoZyBIPsrDWHclWYJx7x4r39ddSORgOMCCtxiC57krjWh7oU
34+
a/KlWZR3MjeLI+ipVT0ltZeT9FArZzeSLXEqW2ENGPk1fWv0SgwPStyQla5244aZ
35+
BDaB3WUr4dVAdWWKEuxoPUQPwEVTgJKJ0/OtC2jPMbE9dFSBz1Iwh5+EuB7PLJTc
36+
PoTb4vMLkFmJntWJIytPDcUgFIpf0Cld8nXICFHUp085zJo182KBkQQWr05SG8p3
37+
5nNuzRE3V00CURrH/SSEa1D3wNlnOYS6klGYzmGLBlb8EoZusb+Lsrd+tLIzqTdV
38+
ciN+qUeEmPLCJEtRexaWVmbUfe7SGJH6VSB7JPEAEQEAAYkCNgQYAQoAIBYhBGSI
39+
gd0EHpnuyQX9gb2ZFISgjpvFBQJl1MpFAhsMAAoJEL2ZFISgjpvFEA8P/2DBEln/
40+
BGBhMyhGMTuLqSb7FqG3yJLD7YTlM2MTGOHinCroOxI3UlS6PQew9o4DkJHaLQw+
41+
ho4qcIol7wISnRHE5fYABcmbdPR3wSIT/KQRdSTVSOkQDFPFGOPRfKeCmKP4npB/
42+
x8LHcoJwG3ab/2axHNkJLWrJwFY6iYxpYIW364v+uSJJq22z3SJ8bmL0JJjr6JPK
43+
SU7Io4deRbnw7q0TNJqcgs4dzmIWaubaA1VdmYbZnq57F6WvTDVwz8vWT45sw4Sy
44+
RML3B2UPxnvHS8sJygnM2Vo+yijU1sYm3yYYAfB81AlbrjGyuGhISR7jnFgAtnuD
45+
HjpGXnDrYKcmjp+EpC88oJiIuuUD6E6AyIXGnXTs00fFCqhcXXwW6wRF7vzo47To
46+
eApHCc0y9A+3ZEfmkpdIsxXdcQNf65Eh0XOB4tEYtmm2hPgjJ3T+1iZRYfsr7dkV
47+
bE//dzBIom0VEr9I8vYlKsqlC0G98AplYvitS++4akCpYFuFXlcKlQErhSGL9qgo
48+
34xrQv//salNPGzDWbOpCDGUQ8DV01FFBkneZIlrz85rR63SPi7mp7SHIW6mGxuA
49+
ZSc8aL5X1m61d4uLTqYswRDJ1nE4ZT05Bk9bpDOzqbELBitU54oPCCNqWEAs+Usq
50+
dhCOLSVqS8XZKOgkOO54MKbmb3YZv5m46DfY
51+
=M91j
52+
-----END PGP PUBLIC KEY BLOCK-----

0 commit comments

Comments
 (0)