Security disclosure

If you have found a security issue in something we run, or you are a researcher coordinating disclosure of a vulnerability we cover, we want to hear from you.

Contact

Email security@crunchbanglinux.org. A PGP key will be published here for encrypted reports.

Coordinated disclosure

For our own original research, we practise coordinated disclosure: we contact the affected vendor or maintainer, allow a reasonable remediation window before publishing, and publish the disclosure timeline and any vendor response alongside our findings.