From 746fb6e38bb4f3a136dfca008c4c6025f3b3a348 Mon Sep 17 00:00:00 2001 From: Spencer Wilson Date: Fri, 3 Jan 2025 11:48:17 -0500 Subject: [PATCH] Add security response process Signed-off-by: Spencer Wilson --- README.md | 4 + security/reports/20241220-hqc-decaps.md | 2 +- security/reports/YYYYMMDD-template.md | 2 +- security/response-process.md | 249 ++++++++++++++++++++++++ 4 files changed, 255 insertions(+), 2 deletions(-) create mode 100644 security/response-process.md diff --git a/README.md b/README.md index 48e6f4a..43096d1 100644 --- a/README.md +++ b/README.md @@ -57,3 +57,7 @@ Subscribe and access list archives at [https://lists.pqca.org/g/oqs-tsc](https:/ ### Discord Join the [PQCA Discord server](https://discord.gg/gv8YN5bb) and reach us on the [#oqs-general](https://discordapp.com/channels/1202723482224295936/1203395992003678238) channel. + +## Security + +OQS responds to security reports following a [coordinated vulnerability disclosure process](security/response-process.md), informed by current Open Source Software Foundation [guidelines](https://github.com/ossf/oss-vulnerability-guide). diff --git a/security/reports/20241220-hqc-decaps.md b/security/reports/20241220-hqc-decaps.md index 5949096..f11ab07 100644 --- a/security/reports/20241220-hqc-decaps.md +++ b/security/reports/20241220-hqc-decaps.md @@ -1,4 +1,4 @@ -# OQS Vulnerability Response Report +# OQS Vulnerability Response Report: 20241220-hqc-decaps