From 5e48a5a786eee433ee51a6c9a664b335b288ec84 Mon Sep 17 00:00:00 2001 From: Paul Schaub Date: Tue, 15 Feb 2022 18:44:58 +0100 Subject: [PATCH] Update SECURITY.md --- SECURITY.md | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 2448191a..59e9adbf 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -13,9 +13,10 @@ Use this section to tell people about which versions of your project are currently being supported with security updates. | Version | Supported | -| ------- | ------------------ | -| 0.2.x | :white_check_mark: | -| < 0.2.0 | :x: | +|---------| ------------------ | +| 1.1.X | :white_check_mark: | +| 1.0.X | :white_check_mark: | +| < 1.0.0 | :x: | ## Reporting a Vulnerability @@ -23,3 +24,11 @@ If you find a security relevant vulnerability inside PGPainless, please let me k [Here](https://keyoxide.org/7F9116FEA90A5983936C7CFAA027DB2F3E1E118A) you can find my OpenPGP key to email me confidentially. Valid security issues will be fixed ASAP. + +## Audits + +### Cure53 - FLO-04 +PGPainless has received a security audit by [cure53.de](https://cure53.de) in late 2021. +The [penetrationj test and audit](https://cure53.de/pentest-report_pgpainless.pdf) covered PGPainless +release candidate 1.0.0-rc6. +Security fixes for discovered flaws were deployed before the final 1.0.0 release. \ No newline at end of file