Skip to content

Commit

Permalink
Update security policy (rust-lang#1133)
Browse files Browse the repository at this point in the history
  • Loading branch information
danielsn authored Apr 29, 2022
1 parent 7cc6568 commit d8f5b04
Show file tree
Hide file tree
Showing 3 changed files with 45 additions and 7 deletions.
6 changes: 6 additions & 0 deletions .github/SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
If you think you have discovered a security issue related to Kani, **please write to us** at [email protected]; do **NOT** open a public issue. Along with your notification email, please provide any supporting material (proof-of-concept code, tool output, etc.) that would be useful in helping us understand the nature and severity of the security concern. Sensitive information can be encrypted using our [PGP key](https://github.com/model-checking/kani/blob/main/kani-verifier-security.public.key).

We will send a non-automated acknowledgement email reply within 1 business day followed by an initial assessment of the issue within 5 business days. Subsequently, we will work in partnership with you to assess any impact of the issue and prepare a security advisory (including any patches with appropriate fix) as needed.

If we confirm that your report represents a security issue in Kani, we will work with you to agree on an embargo period (typically at least 2 weeks AFTER any necessary development time) which will provide enough time to test our proposed fix and develop patches prior to any broader or more public disclosure. At the end of the embargo period, Kani maintainers will publicly release information about the security issue together with the patches that mitigate it.

31 changes: 31 additions & 0 deletions kani-verifier-security.public.key
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v2.0.22 (GNU/Linux)

mQENBGJgjSQBCADGxrzSgt15n9FOOeQeYDhYRQPzF7haV4Pav71x0z9O1y2IlWVZ
x+IVT0biyXPQXiR0kOUpSkJhOg+KUm9QzS8TReSxp40RglYpLxZYt6jFUOdZuJPV
Bvxlrb/OG9ev+DSpOBBdp+oYOFacsEgtmGfEnelRr+725F8WdmmJMc6bm8xH2Ox1
9bPwwn6OSvo8Kp8ebN6bP0wYiq+ooaOw8Muk7zgIOxvpHgnyEpgmkfz4zoxMcRja
peU8IzawiAcBv9cYIrthl+q4G2UrlV9kHGOAwxKyKVnu9YU7jx683wSv8wYAIhht
dqYAYSfLsa4l9/jj45MmnuUHhvNqkUrqs5ahABEBAAG0Nkthbmkgc2VjdXJpdHkg
dGVhbSA8a2FuaS12ZXJpZmllci1zZWN1cml0eUBhbWF6b24uY29tPokBOQQTAQIA
IwUCYmCNJAIbAwcLCQgHAwIBBhUIAgkKCwQWAgMBAh4BAheAAAoJEKF/cGVJsPsV
vxUIAMa9IthQF3fGR5iQHLQgBwQXtSYuVe0yD0IA0tIuwYUo1YLO31ApxzAocXI2
VNVuPIhDI3GCQgR9hfN7phDzQlVHrPt/GKarloWdiMWLkUKl37AzgYdDtcpPHI0X
vZwj6Kk58fVzEenBTuk1silbwgj2xYrs0MP22aa8lxJ5SSreNNqx4CuFjfb+bkja
7EvtQJI/NELYjBXeQWME8pJR+u0s4+0CTlANwfQqUdzX50gKDYA3YbMQpxT1i1Ju
RLAX/ssDb6/0gauQSziptwlYYtRL5w6ybJnPCfOXIEMYco0cF8aSZdFKR0WmHf6f
vUOIYsPNIaYAiD/wlXZBt8DlwZC5AQ0EYmCNJAEIAL2NM0Jj10ppqNdF3Q4FYIEl
KTEyjjSRjgLJ7s05VQbM6ZV2Gh2zrMYTHmUMYk73GhRc4DwWp2hyzdeX4OOocGvO
+ti3BArQPhEZ0NhbTQVPD2zKKq45N5AF1r4ke4lfb7DYNkMEn9xJ9wnj/xeYYlHU
ZhZ3Ac5Y6Z8QbS6f77I65xn4Ui2OftA55JjTlD+IsmqQO+AVhcKfiD5jgAgFLYCI
LERgaNge2yhX+D6S7xTlJCrLpaFec/MgR+PhLXHiZCbV23eQbT3hqPFN5biBGWiT
bFaxLyME+Et+1YvY/Br63PREAT4g9i9jAMyasp6VHx/MQrVtBHHJRvMSlFleFd0A
EQEAAYkBHwQYAQIACQUCYmCNJAIbDAAKCRChf3BlSbD7Fap3CACO1h7eTAsLtsP2
ImzCkN8QJ0HjP/Pu66fgM3rRfxl6aoaeeu95sBf8V4WxjoqKOmwNGOe0obRKghAP
AXh4hwOri+1nr1JXKM2lXmbHP9GGYBtNvvLbWyDTBL50dZM74aAFNHLBHIIHL17U
kKM9WC8Yi+07zrDlcmZXRquAFrN6DR2K7xSkOcwFby0K1rPTUHQJIcGaqvc3j2YP
ZNMVg/ClLAJ456B2VAxbdaJK9RjY9aq3GapOb0Gshi1+48w/Lq2GHbgb3167VOFg
IOan2z2NfbCfasituHMyxTqgTawUR5hu2pV9l7w/Upiepp2TWbhzhgqPmrRMAn3s
YmMgsyBY
=kphk
-----END PGP PUBLIC KEY BLOCK-----
15 changes: 8 additions & 7 deletions scripts/ci/copyright-exclude
Original file line number Diff line number Diff line change
@@ -1,16 +1,17 @@
.clang-format
.diff
.md
.png
.props
expected
ignore
.public.key
Cargo.lock
LICENSE-APACHE
LICENSE-MIT
editorconfig
gitignore
expected
gitattributes
gitignore
gitmodules
LICENSE-APACHE
LICENSE-MIT
Cargo.lock
.png
ignore
scripts/ci/copyright-exclude
tools/make-kani-release/license-notes.txt

0 comments on commit d8f5b04

Please sign in to comment.