Commit Graph

5 Commits

Author SHA1 Message Date
Pablo Zmdl
0440792e4e Introduce security@roundcube.net as security contact
Using a dedicated email address with a dedicated PGP key allows to give
multiple people access while still keeping things under wrap.

A single, private email address as security contact is such a huge bus
factor, which we should avoid. Event just a holiday or illness could
lead to escalation due to missing replies.

Also, in case of potentially severe security issues Nextcloud's security
team must have access to all details and communication. This is already
given for all issues reported via hackerone.com, and with this change is
now also enabled for issues reported by email.
2024-11-05 14:50:57 +01:00
Aleksander Machniak
8d74e52f49 Add additional channel for security issues 2024-01-29 18:04:55 +01:00
Anna
12bdb3010a Update SECURITY.md
Add Nextcloud HackerOne link instead of mail addresses
2023-12-22 20:43:10 +01:00
Josh Soref
203f456620 Spelling (#8001) 2021-04-18 08:43:18 +02:00
Thomas B
e3817a673c Add security policy document 2020-12-19 13:28:19 +01:00