Skip to content

Commit 4b55c15

Browse files
oshaiyogurtearl
andauthored
Create SECURITY.md (#237)
* Create SECURITY.md Co-authored-by: Michael Bailey <[email protected]>
1 parent 30603c7 commit 4b55c15

File tree

1 file changed

+73
-0
lines changed

1 file changed

+73
-0
lines changed

SECURITY.md

Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
## Reporting security issues
2+
3+
Please report security issues related to the project to the
4+
following email address:
5+
6+
ohadshai(at)gmail.com
7+
8+
9+
10+
11+
## Verifying contents
12+
13+
All `kotlin-logging` project artifacts published on Maven central are signed. For
14+
each artifact, there is an associated signature file with the .asc
15+
suffix.
16+
17+
### 2.1.14 +
18+
19+
To verify the signature use [this public key](https://keys.openpgp.org/vks/v1/by-fingerprint/47EB6836245D2D40E89DFB4136D4E9618F3ADAB5).
20+
Here is its fingerprint:
21+
```
22+
pub rsa3072 2021-11-27 [SCEA]
23+
47EB6836245D2D40E89DFB4136D4E9618F3ADAB5
24+
sub rsa3072 2021-11-27 [E]
25+
```
26+
27+
A copy of this key is stored on the
28+
[keys.openpgp.org](https://keys.openpgp.org) keyserver. To add it to
29+
your public key ring use the following command:
30+
31+
```
32+
> FINGER_PRINT=47EB6836245D2D40E89DFB4136D4E9618F3ADAB5
33+
> gpg --keyserver hkps://keys.openpgp.org --recv-keys $FINGER_PRINT
34+
```
35+
36+
### 2.0.8-2.0.11
37+
38+
To verify the signature use [this public key](https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x637b8fb6cd0b57ca1e833e897f083a4ab2af5107).
39+
Here is its fingerprint:
40+
```
41+
pub rsa3072 2021-05-30 [SC]
42+
637B8FB6CD0B57CA1E833E897F083A4AB2AF5107
43+
uid Ohad Shai <[email protected]>
44+
sub rsa3072 2021-05-30 [E]
45+
```
46+
47+
A copy of this key is stored on the
48+
[keyserver.ubuntu.com](https://keyserver.ubuntu.com) keyserver. To add it to
49+
your public key ring use the following command:
50+
51+
```
52+
> FINGER_PRINT=637B8FB6CD0B57CA1E833E897F083A4AB2AF5107
53+
> gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys $FINGER_PRINT
54+
```
55+
### 2.0.2-2.0.7
56+
57+
To verify the signature use [this public key](https://keyserver.ubuntu.com/pks/lookup?op=get&search=0xe52567d2589415bd74eb4c2867631bc0568801c3).
58+
Here is its fingerprint:
59+
```
60+
pub rsa4096 2016-08-29 [SC]
61+
E52567D2589415BD74EB4C2867631BC0568801C3
62+
uid Ohad Shai <[email protected]>
63+
sub rsa4096 2016-08-29 [E]
64+
```
65+
66+
A copy of this key is stored on the
67+
[keyserver.ubuntu.com](https://keyserver.ubuntu.com) keyserver. To add it to
68+
your public key ring use the following command:
69+
70+
```
71+
> FINGER_PRINT=E52567D2589415BD74EB4C2867631BC0568801C3
72+
> gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys $FINGER_PRINT
73+
```

0 commit comments

Comments
 (0)