]> git.ipfire.org Git - thirdparty/pdns.git/blame - SECURITY.md
Merge pull request #14083 from rgacogne/fix-dnsdist-and-rec-home-dirs
[thirdparty/pdns.git] / SECURITY.md
CommitLineData
e61bc786
RG
1PowerDNS and dnsdist Security Policy
2====================================
42fa8581 3
36de301d 4If you have a security problem to report, please email us at both peter.van.dijk@powerdns.com and remi.gacogne@powerdns.com.
035b0046 5In case you want to encrypt your report using PGP, please use: https://doc.powerdns.com/powerdns-keyblock.asc
42fa8581
RG
6
7Please do not mail security issues to public lists, nor file a ticket, unless we do not get back to you in a timely manner.
8We fully credit reporters of security issues, and respond quickly, but please allow us a reasonable timeframe to coordinate a response.
9
e61bc786 10We remind PowerDNS and dnsdist users that under the terms of the GNU General Public License, PowerDNS and dnsdist come with ABSOLUTELY NO WARRANTY.
42fa8581
RG
11This license is included in this documentation.
12
d651e88f
RG
13Yes We Hack
14-----------
15Security issues can also be reported on [our YesWeHack page](https://yeswehack.com/programs/powerdns) and might fetch a bounty.
193e3315 16Do note that only the PowerDNS software (PowerDNS Authoritative Server, the PowerDNS Recursor and dnsdist) is in scope for the YesWeHack program, not our websites or other infrastructure.
42fa8581
RG
17
18Disclosure Policy
19-----------------
20- Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.
21- Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party.
22- We will always credit researchers in our security advisories.