Skip to content

Commit 45c76c1

Browse files
Merge pull request borgbackup#1804 from anarcat/security-notes
move security verification to support section
2 parents c5f5d17 + 319ecd8 commit 45c76c1

File tree

4 files changed

+32
-16
lines changed

4 files changed

+32
-16
lines changed

README.rst

Lines changed: 4 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -113,22 +113,6 @@ Now doing another backup, just to show off the great deduplication:
113113
114114
For a graphical frontend refer to our complementary project `BorgWeb <https://borgweb.readthedocs.io/>`_.
115115

116-
Checking Release Authenticity and Security Contact
117-
--------------------------------------------------
118-
119-
`Releases <https://github.com/borgbackup/borg/releases>`_ are signed with this GPG key,
120-
please use GPG to verify their authenticity.
121-
122-
In case you discover a security issue, please use this contact for reporting it privately
123-
and please, if possible, use encrypted E-Mail:
124-
125-
Thomas Waldmann <[email protected]>
126-
127-
GPG Key Fingerprint: 6D5B EF9A DD20 7580 5747 B70F 9F88 FB52 FAF7 B393
128-
129-
The public key can be fetched from any GPG keyserver, but be careful: you must
130-
use the **full fingerprint** to check that you got the correct key.
131-
132116
Links
133117
-----
134118

@@ -142,6 +126,7 @@ Links
142126
* `Web-Chat (IRC) <http://webchat.freenode.net/?randomnick=1&channels=%23borgbackup&uio=MTY9dHJ1ZSY5PXRydWUa8>`_ and
143127
`Mailing List <https://mail.python.org/mailman/listinfo/borgbackup>`_
144128
* `License <https://borgbackup.readthedocs.org/en/stable/authors.html#license>`_
129+
* `Security contact <https://borgbackup.readthedocs.org/en/stable/support.html#security-contact>`_
145130

146131
Compatibility notes
147132
-------------------
@@ -153,6 +138,9 @@ NOT RELEASED DEVELOPMENT VERSIONS HAVE UNKNOWN COMPATIBILITY PROPERTIES.
153138

154139
THIS IS SOFTWARE IN DEVELOPMENT, DECIDE YOURSELF WHETHER IT FITS YOUR NEEDS.
155140

141+
Security issues should be reported to the `Security contact`_ (or
142+
see ``docs/suppport.rst`` in the source distribution).
143+
156144
|doc| |build| |coverage| |bestpractices|
157145

158146
.. |doc| image:: https://readthedocs.org/projects/borgbackup/badge/?version=stable

docs/faq.rst

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -203,6 +203,13 @@ Thus:
203203
- have media at another place
204204
- have a relatively recent backup on your media
205205

206+
How do I report security issue with |project_name|?
207+
---------------------------------------------------
208+
209+
Send a private email to the :ref:`security-contact` if you think you
210+
have discovered a security issue. Please disclose security issues
211+
responsibly.
212+
206213
Why do I get "connection closed by remote" after a while?
207214
---------------------------------------------------------
208215

docs/installation.rst

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -64,6 +64,9 @@ and compare that to our latest release and review the :doc:`changes`.
6464
Standalone Binary
6565
-----------------
6666

67+
.. note:: Releases are signed with an OpenPGP key, see
68+
:ref:`security-contact` for more instructions.
69+
6770
|project_name| binaries (generated with `pyinstaller`_) are available
6871
on the releases_ page for the following platforms:
6972

docs/support.rst

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,3 +56,21 @@ As a developer, you can become a Bounty Hunter and win bounties (earn money) by
5656
contributing to |project_name|, a free and open source software project.
5757

5858
We might also use BountySource to fund raise for some bigger goals.
59+
60+
.. _security-contact:
61+
62+
Security
63+
--------
64+
65+
In case you discover a security issue, please use this contact for reporting it privately
66+
and please, if possible, use encrypted E-Mail:
67+
68+
Thomas Waldmann <[email protected]>
69+
70+
GPG Key Fingerprint: 6D5B EF9A DD20 7580 5747 B70F 9F88 FB52 FAF7 B393
71+
72+
The public key can be fetched from any GPG keyserver, but be careful: you must
73+
use the **full fingerprint** to check that you got the correct key.
74+
75+
`Releases <https://github.com/borgbackup/borg/releases>`_ are signed with this GPG key,
76+
please use GPG to verify their authenticity.

0 commit comments

Comments
 (0)