Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport change to SECURITY.md #9694

Merged
merged 1 commit into from
Nov 6, 2024

Conversation

pabzm
Copy link
Member

@pabzm pabzm commented Nov 6, 2024

Backport of #9690 to branch release-1.6.

The change is a little bigger than in the original PR/commit, because in branch release-1.6 a much older version of the file was still present. Now the files in both branches are identical.

Using a dedicated email address with a dedicated PGP key allows to give
multiple people access while still keeping things under wrap.

A single, private email address as security contact is such a huge bus
factor, which we should avoid. Event just a holiday or illness could
lead to escalation due to missing replies.

Also, in case of potentially severe security issues Nextcloud's security
team must have access to all details and communication. This is already
given for all issues reported via hackerone.com, and with this change is
now also enabled for issues reported by email.

(cherry picked from commit 0440792)
@pabzm pabzm requested a review from alecpl November 6, 2024 15:42
@pabzm
Copy link
Member Author

pabzm commented Nov 6, 2024

@alecpl I'd leave managing release-1.6 to you, if you don't mind?

@alecpl alecpl merged commit fc6c34b into release-1.6 Nov 6, 2024
12 of 14 checks passed
@alecpl
Copy link
Member

alecpl commented Nov 6, 2024

Sure.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants