Skip to content

Security: tpm2-software/tpm2-tss

SECURITY.md

Security Policy

Supported Versions

We provide patch updates for each minor release for at least one year from its initial release. Check the initial release date for your minor version at:

Reporting a Vulnerability

The preferred method is to report security vulnerabilities by opening a GitHub Security Advisory (GHSA) to coordinate disclosure. Alternatively, write an encrypted email to all maintainers using the keys listed in MAINTAINERS.

Please do not create temporary private forks when coordinating a GHSA. They complicate mitigation and release coordination and clutter the organization's repository list.

Security Reporting Guidelines

Tracking

When a maintainer is notified of a security vulnerability, they must create a GitHub Security Advisory (GHSA) per the instructions at:

Maintainers should use GitHub's optional feature to request that a CVE be issued. Alternatively, Red Hat has acted as a CNA for us in the past, but GitHub is the preferred issuing CNA.

Publishing

Before publication, maintainers must ensure the GHSA summary contains no proof-of-concept (PoC) exploit code and must move any such code to a private comment on the advisory.

Once ready, maintainers should publish the security advisory as outlined at:

Maintainers must ensure the CVE is published and have new release versions ready to publish at the same time as the advisory/CVE. Maintainers should strive to keep the turnaround from report to release under 60 days.

Reporters are credited unless they request otherwise.

Learn more about advisories related to tpm2-software/tpm2-tss in the GitHub Advisory Database