From: Ahmad Fatoum <[email protected]> SECURITY.md says where to report vulnerabilities, but not what counts as one. The README says nothing about security.
Link the new threat model from both files. In the README, add a short Security section that also links the Security Considerations chapter. Signed-off-by: Ahmad Fatoum <[email protected]> --- README.rst | 10 ++++++++++ SECURITY.md | 6 ++++++ 2 files changed, 16 insertions(+) diff --git a/README.rst b/README.rst index fe783028dfad..1800f5e51822 100644 --- a/README.rst +++ b/README.rst @@ -284,6 +284,16 @@ are the release rules: does never change, in order to make life easier for distribution people. +Security +-------- + +The `threat model <https://www.barebox.org/doc/latest/user/threat-model.html>`_ +describes what barebox does and does not protect against and which bugs are +considered security vulnerabilities. The +`Security Considerations <https://www.barebox.org/doc/latest/user/security.html>`_ +chapter describes how to configure barebox for verified boot. Refer to +``SECURITY.md`` for how to report vulnerabilities. + .. _contributing: Contributing diff --git a/SECURITY.md b/SECURITY.md index 862dd14623d9..39407514a361 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -19,7 +19,13 @@ releases: Please report security vulnerabilities to [email protected]. We will work with the reporter to create a fix and to coordinate the disclosure. +The [threat model](https://www.barebox.org/doc/latest/user/threat-model.html) +describes what barebox does and does not protect against and which classes of +bugs are not vulnerabilities. Report those as ordinary bugs on the +[mailing list](https://www.barebox.org/doc/latest/user/introduction.html#feedback). + ## Securing barebox Refer to the [Security Considerations](https://www.barebox.org/doc/latest/user/security.html) chapter of the documentation for information on how to configure barebox securely. +That advice relies on the assumptions listed in the threat model. -- 2.47.3
