Skip to content

Commit b14996a

Browse files
authored
Add security contact
A way to report security issues for trivrost.
1 parent 5d2d50d commit b14996a

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

docs/security.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,8 @@
1+
# Reporting security issues
2+
In case you discover a security issue, please use this contact for reporting it privately:
3+
4+
Setlog team SWAT <swat(#at)setlog.com>
5+
16
# Security of trivrost
27
To secure trivrost, you should only use it via https. However, to increase the security the deployment-config and the bundle info files have to be digitally signed. This way, every download is cryptographically secured. Furthermore, the deployment-config and the bundle info files must contain a timestamp to further strengthen the security.
38

0 commit comments

Comments
 (0)