Give researchers a safe path.
Reports should have a clear scope, channel, expected contents, and coordinated timeline.
Trustworthy infrastructure needs a clear path for disclosure, signed releases, supported versions, and coordinated remediation.
This center is the public index for vulnerability disclosure, advisories, supported versions, release keys, and verification material.
Do not send sensitive security details through an unverified channel. The disclosure path will be published before reports are solicited at this domain.
Reports should have a clear scope, channel, expected contents, and coordinated timeline.
Release keys and digests make it possible to check what was published.
Advisories and supported versions make changes legible to users.
There are currently no published security advisories.
Public fingerprints will appear before signed release verification is enabled.