Files
wolfssl/.github/SECURITY.md
T
Mark Atwood 66fe117538 docs: keep in-repo security policy, fix contacts
Address review feedback (dgarske):

- Restore SECURITY-POLICY.md instead of deleting it. The full policy
  (severity rubric, scope, coordinated disclosure, credit) stays in-repo;
  the canonical website URL is now presented as a mirror of it, not a
  replacement, so other repos can still reference one copy.
- SECURITY.md: prefer support@wolfssl.com, offer secure@wolfssl.com with
  the PGP key as an option, and drop the phone number.
- Restore the mandatory report-template requirement and the "keep the
  vulnerability private until a fix is released" guidance, resolving the
  contradiction between the intro and the template section.
2026-07-09 12:39:30 -07:00

1.1 KiB

Security Policy

Reporting a Vulnerability

Use of the wolfSSL Vulnerability Report Template is mandatory. All security reports must use SECURITY-REPORT-TEMPLATE.md, with every required field completed. Reports that do not use the template, or that leave required fields incomplete, will not receive CVE consideration.

Submit the completed template to support@wolfssl.com. You may also send it to secure@wolfssl.com and encrypt it with our PGP key:

Fingerprint: A2A4 8E7B CB96 C5BE CB98 7314 EBC8 0E41 5CA2 9677
Key server: keys.openpgp.org

Non-template submissions may still be reviewed on the merits and, where appropriate, addressed as hardening fixes in a future release.

Please keep the vulnerability private until a fix has been released.

Full Policy

For the full policy — severity rubric, scope, coordinated-disclosure practice, and reporter credit — see SECURITY-POLICY.md. The same policy is also published at https://www.wolfssl.com/.well-known/vulnerability-disclosure-policy.txt so that other wolfSSL repositories can reference one canonical copy.