From 6dc844093829fcbae709b24a687aaff6e7cdb000 Mon Sep 17 00:00:00 2001 From: Martin Holst Swende Date: Wed, 5 Jun 2019 09:01:21 +0200 Subject: [PATCH] docs: more info on security.md file --- SECURITY.md | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/SECURITY.md b/SECURITY.md index 4472f23c5b..bc54ede42f 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -2,8 +2,24 @@ ## Supported Versions +Please see Releases. We recommend to use the most recent released version. + +## Audit reports + +Audit reports are published in the `docs` folder: https://github.com/ethereum/go-ethereum/tree/master/docs/audits + + +| Scope | Date | Report Link | +| ------- | ------- | ----------- | +| `geth` | 20170425 | [pdf](https://github.com/ethereum/go-ethereum/blob/master/docs/audits/2017-04-25_Geth-audit_Truesec.pdf) | +| `clef` | 20180914 | [pdf](https://github.com/ethereum/go-ethereum/blob/master/docs/audits/2018-09-14_Clef-audit_NCC.pdf) | + + + ## Reporting a Vulnerability +**Please do not file a public ticket** mentioning the vulnerability. + To find out how to disclose a vulnerability in Ethereum visit [https://bounty.ethereum.org](https://bounty.ethereum.org) or email bounty@ethereum.org. The following key may be used to communicate sensitive information to developers.