RoundCube Webmail
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

18 lines
967 B

  1. # Security Policy
  2. ## Supported Versions
  3. Check our website's [download page](https://roundcube.net/download/) to see which versions are still supported and will receive security updates.
  4. ## Reporting a Vulnerability
  5. If you found a security issue or vulnerability of the software, please report with direct and encrypted email to *thomas[at]roundcube.net*
  6. and *alec[at]alec.pl*. You can find the according PGP public keys on the major public keyservers like [pgp.key-server.io](https://pgp.key-server.io).
  7. Your report should include clear steps for reproduction and a classification of the found vulnerability.
  8. ## Publishing and Credits
  9. We're dedicated to analyze and fix the reported issues as fast a possible. Usually within days we'll have an update ready.
  10. Together with the reporter we plan the releasing and the disclosure of the found and fixed vulnerability.
  11. Credits to the reporter are granted and can be included in all public communication if desired.