Skip to content

Conversation

@pietroalbini
Copy link
Member

The PR makes multiple changes to our security policy:

  • Clarifies which branches we support (latest stable, beta, nightly).
  • Clarifies we only email distros@openwall when the vulnerability is relevant to them (this is our standard practice anyway).
  • Mentions that we loop relevant members of the Rust team in vulnerabilities, who review the fixes.
  • Removes the 6 hours delay notice for the blog post, as in the last few years we always published it at the same time as the announcement in the mailing list.
  • Adds information on when we publish CVE records, as requested by MITRE.
  • Removes the prompt to encrypt emails with gpg.

cc @rust-lang/security

@pietroalbini pietroalbini requested a review from a team as a code owner July 28, 2025 10:23
@Manishearth Manishearth merged commit baa8db4 into master Jul 28, 2025
2 checks passed
@Manishearth Manishearth deleted the pa-security-updates branch July 28, 2025 13:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants