Commit 7762ad329d for strongswan.org
commit 7762ad329d5b122092871212b667b8e1be008c71
Author: Tobias Brunner <tobias@strongswan.org>
Date: Mon Sep 28 10:13:48 2026 +0200
SECURITY: Update links and clarify process
diff --git a/SECURITY.md b/SECURITY.md
index ff8088fa91..6873d8a019 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -3,7 +3,7 @@
## Reporting a Vulnerability
Please report any security-relevant flaw to security@strongswan.org. Whenever
-possible encrypt your email with the [PGP key](https://download.strongswan.org/STRONGSWAN-SECURITY-PGP-KEY)
+possible encrypt your email with the [strongSwan security PGP key](https://download.strongswan.org/STRONGSWAN-SECURITY-PGP-KEY)
with key ID 0x1EB41ECF25A536E4.
## Severity Classification
@@ -30,19 +30,19 @@ with key ID 0x1EB41ECF25A536E4.
## Action Taken
For **high** and **medium** severity vulnerabilities we are generally going to
-apply for a [CVE Identifier](https://cve.mitre.org/cve/identifiers/) first.
-Next we notify all known strongSwan customers and the major Linux
-distributions, giving them a time of about three weeks to patch their software
-release. On a predetermined date, we officially issue an advisory and a patch
-for the vulnerability and usually a new stable strongSwan release containing
-the security fix.
+apply for a [CVE Identifier](https://www.cve.org/). On a predetermined date,
+we officially issue an advisory and a patch for the vulnerability and usually
+a new stable strongSwan release containing the security fix. We will notify all
+known strongSwan license customers and the major Linux distributions about two
+weeks before the publication to allow them to patch their software release.
Minor vulnerabilities of **low** severity usually will be fixed immediately
in our repository and released with the next stable release.
-## List of Reported and Fixed Security Flaws
+## List of Published and Fixed Security Flaws
-A list of all reported strongSwan high and medium security flaws may be
-found in the [CVE database](https://nvd.nist.gov/vuln/search/results?query=strongswan).
-
-The corresponding security patches are published on https://download.strongswan.org/security/.
+A list of all published strongSwan high and medium security flaws can be found
+[on our website](https://strongswan.org/security/), as can the corresponding
+[security patches and OSV files](https://download.strongswan.org/security/).
+Each security patch is signed by the
+[strongSwan release PGP key](https://download.strongswan.org/STRONGSWAN-RELEASE-PGP-KEY).