Testsuite: better sorting for exim_dumpdb output
[exim.git] / SECURITY.md
CommitLineData
3ff0668b
PP
1# Security Policy
2
3## Supported Versions
4
5We are an open source project with no corporate sponsor and no formal
6"support". In practice, we support the latest released version and work with
7OS vendors to make it easy for them to backport fixes for their distributed
8packages. For some security issues, we will issue a patch-release which has
9just a simple fix.
10
275dd1de 11We also often have `exim-VERSION+fixes` branches with small things which we
3ff0668b
PP
12recommend that vendors use.
13
14For postmasters installing Exim manually, we recommend always using the latest
15released tarball.
16
17## Reporting a Vulnerability
18
19Our security page is at <https://wiki.exim.org/EximSecurity>.
20It contains the current contact point and list of PGP keys to use for
21encrypting particularly sensitive information.
22This also links to our documentation and the chapter on security
23considerations.
24
25Our security release process is at
26<https://wiki.exim.org/SecurityReleaseProcess>.
27This covers what we do in handling vulnerability reports.
28
29We have no bug bounty program of our own; we're far too disparate a group of
30volunteers for such things.