Skip to content

Conversation

pietroalbini
Copy link
Member

The PR makes multiple changes to our security policy:

  • Clarifies which branches we support (latest stable, beta, nightly).
  • Clarifies we only email distros@openwall when the vulnerability is relevant to them (this is our standard practice anyway).
  • Mentions that we loop relevant members of the Rust team in vulnerabilities, who review the fixes.
  • Removes the 6 hours delay notice for the blog post, as in the last few years we always published it at the same time as the announcement in the mailing list.
  • Adds information on when we publish CVE records, as requested by MITRE.
  • Removes the prompt to encrypt emails with gpg.

cc @rust-lang/security

@pietroalbini pietroalbini requested a review from a team as a code owner July 28, 2025 10:23
@Manishearth Manishearth merged commit baa8db4 into master Jul 28, 2025
2 checks passed
@Manishearth Manishearth deleted the pa-security-updates branch July 28, 2025 13:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants