Report suspected vulnerabilities in any O'Shaughnessy Lab product privately to [email protected].
For confidential details, encrypt your mail to the security team's PGP key:
367EA3D227DBD07894F47A378D65CACD093C39C9Verify the fingerprint against this page before trusting the key. If keys.openpgp.org is unreachable, the same key is also published at https://github.com/oslabteam.gpg, and the Lab's other public keys, including the support key used for support bundles, are at https://github.com/oslabteam.keys.
The affected product, revision or version, the impact, and reproduction details where possible.
Do not disclose vulnerabilities in public issues or pull requests.
No fixed response time or fix deadline is promised. A per-product security-maintenance policy is recorded in the product's repository when one exists.
For vulnerabilities in upstream Talos Linux rather than O'Shaughnessy Lab's fork, follow the upstream security policy.