diff --git a/SECURITY.md b/SECURITY.md index d957c23cf2..fa0e866a3f 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -3,14 +3,14 @@ ## Supported versions -LXD has two types of releases: +Incus has two types of releases: -- Monthly feature releases +- Feature releases - LTS releases For feature releases, only the latest one is supported, and we usually don't do point releases. Instead, users are expected to wait until the -next monthly release. +next release. For LTS releases, we do periodic bugfix releases that include an accumulation of bugfixes from the feature releases. Such bugfix releases @@ -26,11 +26,9 @@ This doesn't mean that we're not interested in preventing such escapes, but we simply do not consider such containers to be root safe. Unprivileged container escapes are certainly something we'd consider a -security issue, especially if somehow facilitated by LXD. +security issue, especially if somehow facilitated by Incus. -## Ubuntu Security disclosure and embargo policy +## Reporting security issues -See the [Ubuntu Security disclosure and embargo -policy](https://ubuntu.com/security/disclosure-policy) for information -about how to contact the Ubuntu Security Team, what you can expect when -you contact us, and what we expect from you. +Security issues can be reported by e-mail to security@linuxcontainers.org. +Alternatively security issues can also be reported through Github at: https://github.com/lxc/incus/security/advisories/new