Skip to content

Commit d098d01

Browse files
authored
docs(security): update disclosure contacts and reporting requirements (#11174)
2 parents 9487509 + 53a47b7 commit d098d01

2 files changed

Lines changed: 50 additions & 27 deletions

File tree

AGENTS.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -60,6 +60,22 @@ The contribution gate already defines discussion/issue requirements. Additional
6060
- Missing test evidence for behavior changes
6161
- Inability to explain the logic or design tradeoffs of the changes when asked
6262

63+
## Security Vulnerability Reports
64+
65+
If you or the user believe you have found a security vulnerability in Zebra,
66+
do not open a public issue or PR. Follow the reporting process in
67+
[SECURITY.md](SECURITY.md).
68+
69+
Before helping a user submit a report, hold it to the same standard as
70+
SECURITY.md's "Before You Report" section:
71+
72+
- Verify the issue reproduces against the latest Zebra release or the current
73+
`main` branch — not an older release, fork, or modified build.
74+
- Run any proof of concept against one of those two versions and include the
75+
exact release version or `main` commit hash tested in the report.
76+
- Do not submit speculative findings. "This code looks vulnerable" without a
77+
reproduction against current code wastes triage time and may be dismissed.
78+
6379
## AI Disclosure
6480

6581
If AI tools were used to write code, tests, or PR descriptions, disclose this in the PR description. Specify the tool and scope (e.g., "Used Claude for test boilerplate"). The contributor is the sole responsible author — "the AI generated it" is not a justification during review.

SECURITY.md

Lines changed: 34 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -24,10 +24,25 @@ appropriate timeline and perform a coordinated release, giving credit to the
2424
reporter if they would like. We align our reporting channels with the broader
2525
Zcash ecosystem disclosure process.
2626

27+
### Before You Report
28+
29+
Before submitting a report, confirm that the issue affects the latest Zebra
30+
release (<https://github.com/ZcashFoundation/zebra/releases/latest>) or the
31+
current `main` branch. Any proof of concept must be tested against one of
32+
those two versions — reports reproduced only on older releases, forks, or
33+
modified builds may not represent a vulnerability in current code and take
34+
substantially longer to triage.
35+
36+
In your report, state the exact release version or `main` commit hash you
37+
tested against.
38+
2739
For critical vulnerabilities, notify us on Signal. Create a new Signal group
28-
(do not reuse a previous group for a separate issue) that includes:
40+
(do not reuse a previous group for a separate issue) that includes all of the
41+
following handles:
2942

3043
- `pilizcash.01`
44+
- `conrado.42`
45+
- `dc_zf.77`
3146

3247
Treat a vulnerability as critical if it could cause consensus divergence or a
3348
chain split, loss or counterfeiting of funds, a persistent node halt, state
@@ -42,31 +57,24 @@ primary or fully reliable reporting channel, so use it only when the channels
4257
above are unavailable. The key may also be used to encrypt follow-up material
4358
once contact is established.
4459

60+
The key is `Zcash Foundation Security Team <security@zfnd.org>`, fingerprint
61+
`7550 C36C 3DF6 16A6 9F1E FE00 6046 DDEF 94CF 99B5`, valid until 2028-03-03.
62+
Verify the fingerprint before encrypting to this key.
63+
4564
```
4665
-----BEGIN PGP PUBLIC KEY BLOCK-----
4766
48-
mDMEaXswoxYJKwYBBAHaRw8BAQdA/CQqZ79S7A9OWZeYhY3AbMuTx2d41/pcehNc
49-
Z1ZF7r6IeAQgFgoAIBYhBOezJEDaeE6/uKooRf1tVVkb+SvKBQJpezIJAh0AAAoJ
50-
EP1tVVkb+SvKmqQBAMzp/pOZ/ifM0Tjuqzy4nTo8HT5xZwTfL84A40VURuElAP91
51-
/9wi+5ZKW09pdjHjag6tz0FhheinX1BEDbgww2u3CbQkWmNhc2ggRm91bmRhdGlv
52-
biA8c2VjdXJpdHlAemZuZC5vcmc+iJYEExYKAD4WIQTnsyRA2nhOv7iqKEX9bVVZ
53-
G/krygUCaXswowIbAwUJACeNAAULCQgHAwUVCgkICwUWAgMBAAIeAQIXgAAKCRD9
54-
bVVZG/kryrS4AQCiyknTREsLCICWdbaJUARuZifhDxXIKH0oest8y8HQQwD9HuRd
55-
936Cg5FbXHpBuF71fGU213OSgulG4+hr7rXdfgy4OARpezCjEgorBgEEAZdVAQUB
56-
AQdAw5WBljp9hoqi8lu2KU5QzNuv/1lpeGWoESdWg/GZKUIDAQgHiH4EGBYKACYW
57-
IQTnsyRA2nhOv7iqKEX9bVVZG/krygUCaXswowIbDAUJACeNAAAKCRD9bVVZG/kr
58-
yjsWAQCiRiecQ9P3DPyQ/E/N0Dl3z4jE2fM2NjhROnX4jB/lDgD8Cru6rg2sdxTc
59-
RHrjNOriwH3PxwALJorvERC1gl47jQ2YMwRpqByGFgkrBgEEAdpHDwEBB0DV0fxs
60-
U5skejT0UERNZbec7GGe7Vs7s1h0moC4vkuY87QyWmNhc2ggRm91bmRhdGlvbiBT
61-
ZWN1cml0eSBUZWFtIDxzZWN1cml0eUB6Zm5kLm9yZz6IlgQTFgoAPhYhBHVQw2w9
62-
9hamnx7+AGBG3e+Uz5m1BQJpqByGAhsDBQkDwmcABQsJCAcDBRUKCQgLBRYCAwEA
63-
Ah4BAheAAAoJEGBG3e+Uz5m18MoBAOulghTZ717buHwBKBZupdXMdYPZcNSxlFC1
64-
+ROt3iYAAP0RfQPw/UYLQlsnc5JEov2pExVpdXJH4waJjh+r26ZQCbg4BGmoHIYS
65-
CisGAQQBl1UBBQEBB0BXtdSydYIV586tkyNwAefvnQM0pJapklUbVD9f9AmQHAMB
66-
CAeIfgQYFgoAJhYhBHVQw2w99hamnx7+AGBG3e+Uz5m1BQJpqByGAhsMBQkDwmcA
67-
AAoJEGBG3e+Uz5m14rEA/0x/2XNwKd4buCm1tOGpTMaLQRoWhos6L/0wV9LExEKG
68-
AQC1Wmyb9ul/2QNi//8sKNDfaYbn3h6OU45BTAWggp+ACQ==
69-
=RIK0
67+
mDMEaagchhYJKwYBBAHaRw8BAQdA1dH8bFObJHo09FBETWW3nOxhnu1bO7NYdJqA
68+
uL5LmPO0MlpjYXNoIEZvdW5kYXRpb24gU2VjdXJpdHkgVGVhbSA8c2VjdXJpdHlA
69+
emZuZC5vcmc+iJYEExYKAD4WIQR1UMNsPfYWpp8e/gBgRt3vlM+ZtQUCaagchgIb
70+
AwUJA8JnAAULCQgHAwUVCgkICwUWAgMBAAIeAQIXgAAKCRBgRt3vlM+ZtfDKAQDr
71+
pYIU2e9e27h8ASgWbqXVzHWD2XDUsZRQtfkTrd4mAAD9EX0D8P1GC0JbJ3OSRKL9
72+
qRMVaXVyR+MGiY4fq9umUAm4OARpqByGEgorBgEEAZdVAQUBAQdAV7XUsnWCFefO
73+
rZMjcAHn750DNKSWqZJVG1Q/X/QJkBwDAQgHiH4EGBYKACYWIQR1UMNsPfYWpp8e
74+
/gBgRt3vlM+ZtQUCaagchgIbDAUJA8JnAAAKCRBgRt3vlM+ZteKxAP9Mf9lzcCne
75+
G7gptbThqUzGi0EaFoaLOi/9MFfSxMRChgEAtVpsm/bpf9kDYv//LCjQ32mG594e
76+
jlOOQUwFoIKfgAk=
77+
=K4Oq
7078
-----END PGP PUBLIC KEY BLOCK-----
7179
```
7280

@@ -80,11 +88,10 @@ In the case where we fix a security issue in Zebra or Zcash that also affects th
8088

8189
We have set up agreements with the following neighboring projects to share vulnerability information, subject to the deviations described in the next section.
8290

83-
Specifically, we have agreed to engage in responsible disclosures for security issues affecting Zebra or Zcash technology with the following contacts:
91+
Specifically, we have agreed to engage in responsible disclosures for security issues affecting Zebra or Zcash technology with the following teams:
8492

85-
- Zcash Open Development Lab (ZODL), which maintains the `zcash/zcash` core
86-
node, `librustzcash`, `zallet`, and related software, via its security
87-
disclosure process at <https://github.com/zcash/.github/blob/main/SECURITY.md>
93+
- Zcash Open Development Lab (ZODL), which maintains the `zcash/zcash` core node, `librustzcash`, `zallet`, and related software, via its security disclosure process at <https://github.com/zcash/.github/blob/main/SECURITY.md>
94+
- Shielded Labs, which maintains the Crosslink proof-of-stake and Network Sustainability Mechanism work and its associated Zebra and `librustzcash` forks.
8895

8996
## Deviations from the Standard
9097

0 commit comments

Comments
 (0)