Skip to content

Commit 08210da

Browse files
ShahanaFarooquirustyrussell
authored andcommitted
docs: Update Security Information
Changelog-None.
1 parent b261e82 commit 08210da

File tree

2 files changed

+24
-11
lines changed

2 files changed

+24
-11
lines changed

README.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,9 @@ Core Lightning (previously c-lightning) is a lightweight, highly customizable an
2828
[![Irc][IRC-badge]][IRC]
2929

3030
This implementation has been in production use on the Bitcoin mainnet since early 2018, with the launch of the [Blockstream Store][blockstream-store-blog].
31-
We recommend getting started by experimenting on `testnet` (or `regtest`), but the implementation is considered stable and can be safely used on mainnet.
31+
We recommend getting started by experimenting on `testnet` (`testnet4` or `regtest`), but the implementation is considered stable and can be safely used on mainnet.
32+
33+
## Reach Out to Us
3234

3335
Any help testing the implementation, reporting bugs, or helping with outstanding issues is very welcome.
3436
Don't hesitate to reach out to us on [Build-on-L2][bol2], or on the implementation-specific [mailing list][ml1], or on [CLN Discord][discord], or on [CLN Telegram][telegram], or on IRC at [dev][irc1]/[gen][irc2] channel.

SECURITY.md

Lines changed: 21 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -6,19 +6,30 @@ We have a 3 month release cycle, and the last two versions are supported.
66

77
## Reporting a Vulnerability
88

9-
To report security issues send an email to [email protected], or
10-
[email protected] (not for support).
9+
To report security vulnerabilities, please send an email to one of the following addresses:
10+
11+
12+
13+
Note: These email addresses are exclusively for vulnerability reporting.
14+
15+
For all other inquiries/communication, please refer to the [Reach Out to Us](https://github.com/ElementsProject/lightning?tab=readme-ov-file#reach-out-to-us) section in our README.
1116

1217
## Signatures For Releases
1318

1419
The following keys may be used to communicate sensitive information to
1520
developers, and to validate signatures on releases:
1621

17-
| Name | Fingerprint |
18-
|------|-------------|
19-
| Rusty Russell | 15EE 8D6C AB0E 7F0C F999 BFCB D920 0E6C D1AD B8F1 |
20-
| Christian Decker | B731 AAC5 21B0 1385 9313 F674 A26D 6D9F E088 ED58 |
21-
| Lisa Neigut | 30DE 693A E0DE 9E37 B3E7 EB6B BFF0 F678 10C1 EED1 |
22-
| Alex Myers | 0437 4E42 789B BBA9 462E 4767 F3BF 63F2 7474 36AB |
23-
24-
You can import a key by running the following command with that individual’s fingerprint: `gpg --keyserver hkps://keys.openpgp.org --recv-keys "<fingerprint>"` Ensure that you put quotes around fingerprints containing spaces.
22+
| Name | Email | Fingerprint |
23+
|------|-------|-------------|
24+
| Blockstream Security Reporting | `[email protected]` | 1176 542D A98E 71E1 3372 2EF7 4AC8 CC88 6844 A2D6 |
25+
| Rusty Russell | `[email protected]` | 15EE 8D6C AB0E 7F0C F999 BFCB D920 0E6C D1AD B8F1 |
26+
| Christian Decker | `[email protected]` | B731 AAC5 21B0 1385 9313 F674 A26D 6D9F E088 ED58 |
27+
| Lisa Neigut | `[email protected]` | 30DE 693A E0DE 9E37 B3E7 EB6B BFF0 F678 10C1 EED1 |
28+
| Alex Myers | `[email protected]` | 0437 4E42 789B BBA9 462E 4767 F3BF 63F2 7474 36AB |
29+
| Peter Neuroth | `[email protected]` | 653B 19F3 3DF7 EFF3 E9D1 C94C C3F2 1EE3 87FF 4CD2 |
30+
| Shahana Farooqui | `[email protected]` | FE13 58EB 7793 51DB 24E5 555A A327 573C 9758 9BF5 |
31+
| Blockstream CLN Release | `[email protected]` | 616C 52F9 9D06 12B2 A151 B107 4129 A994 AA7E 9852 |
32+
33+
You can import a key by running the following command with that individual’s fingerprint:
34+
`gpg --keyserver hkps://keys.openpgp.org --recv-keys "<fingerprint>"`.
35+
Ensure that you put quotes around fingerprints containing spaces.

0 commit comments

Comments
 (0)