mirror of
https://github.com/QubesOS/qubes-doc.git
synced 2025-10-11 10:08:39 -04:00
Merge branch 'master' into spelling-grammar-fixes
Resolved conflicts in: basics_user/doc-guidelines.md basics_user/reporting-bugs.md common-tasks/backup-restore.md common-tasks/software-update-dom0.md common-tasks/software-update-vm.md common-tasks/usb.md configuration/disk-trim.md configuration/external-audio.md configuration/network-printer.md configuration/resize-disk-image.md configuration/resize-root-disk-image.md customization/fedora-minimal-template-customization.md managing-os/hvm.md managing-os/templates/archlinux.md privacy/whonix-install.md security/yubi-key.md troubleshooting/install-nvidia-driver.md troubleshooting/macbook-troubleshooting.md
This commit is contained in:
commit
919f2ed17e
123 changed files with 2914 additions and 1254 deletions
|
@ -34,4 +34,5 @@ Qubes Canaries are published through the [Qubes Security Pack](/security/pack/).
|
|||
- [Qubes Canary \#11](https://github.com/QubesOS/qubes-secpack/blob/master/canaries/canary-011-2017.txt)
|
||||
- [Qubes Canary \#12](https://github.com/QubesOS/qubes-secpack/blob/master/canaries/canary-012-2017.txt)
|
||||
- [Qubes Canary \#13](https://github.com/QubesOS/qubes-secpack/blob/master/canaries/canary-013-2017.txt)
|
||||
- [Qubes Canary \#14](https://github.com/QubesOS/qubes-secpack/blob/master/canaries/canary-014-2017.txt)
|
||||
|
||||
|
|
|
@ -81,5 +81,11 @@ Qubes Security Bulletins are published through the [Qubes Security Pack](/securi
|
|||
- [Qubes Security Bulletin \#32](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-032-2017.txt) (Xen hypervisor and Linux kernel vulnerabilities (XSA-226 through XSA-230))
|
||||
- [Qubes Security Bulletin \#33](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-033-2017.txt) (Xen hypervisor (XSA-231 through XSA-234))
|
||||
- [Qubes Security Bulletin \#34](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-034-2017.txt) (GUI issue and Xen vulnerabilities (XSA-237 through XSA-244))
|
||||
- [Qubes Security Bulletin \#34](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-035-2017.txt) (Xen hypervisor issue related to grant tables (XSA-236))
|
||||
- [Qubes Security Bulletin \#35](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-035-2017.txt) (Xen hypervisor issue related to grant tables (XSA-236))
|
||||
- [Qubes Security Bulletin \#36](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-036-2017.txt) (Xen hypervisor issue in populate-on-demand code (XSA-247))
|
||||
|
||||
2018
|
||||
----
|
||||
|
||||
- [Qubes Security Bulletin \#37](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-037-2018.txt) (Information leaks due to processor speculative execution bugs)
|
||||
|
||||
|
|
|
@ -17,37 +17,53 @@ redirect_from:
|
|||
Qubes OS Project Security Center
|
||||
================================
|
||||
|
||||
- [Security Goals](/security/goals/)
|
||||
- [Security Pack](/security/pack/)
|
||||
- [Security Bulletins](/security/bulletins/)
|
||||
- [Canaries](/security/canaries/)
|
||||
- [Xen Security Advisory (XSA) Tracker](/security/xsa/)
|
||||
- [Why and How to Verify Signatures](/security/verifying-signatures/)
|
||||
- [PGP Keys](https://keys.qubes-os.org/keys/)
|
||||
- [Security FAQ]
|
||||
- [Security Goals]
|
||||
- [Security Pack]
|
||||
- [Security Bulletins]
|
||||
- [Canaries]
|
||||
- [Xen Security Advisory (XSA) Tracker]
|
||||
- [Why and How to Verify Signatures]
|
||||
- [PGP Keys]
|
||||
|
||||
|
||||
Reporting Security Issues in Qubes OS
|
||||
-------------------------------------
|
||||
|
||||
If you believe you have found a security issue affecting Qubes OS, either directly or indirectly (e.g. the issue affects Xen in a configuration that is used in Qubes OS), then we would be more than happy to hear from you!
|
||||
We promise to treat any reported issue seriously and, if the investigation confirms that it affects Qubes, to patch it within a reasonable time and release a public [Qubes Security Bulletin][Security Bulletins] that describes the issue, discusses the potential impact of the vulnerability, references applicable patches or workarounds, and credits the discoverer.
|
||||
|
||||
We promise to treat any reported issue seriously and, if the investigation confirms it affects Qubes, to patch it within a reasonable time, release a public Security Bulletin that describes the issue, discuss potential impact of the vulnerability, reference applicable patches or workarounds, and credit the discoverer.
|
||||
|
||||
The list of all Qubes Security Advisories published so far can be found [here](/security/bulletins/).
|
||||
|
||||
The Qubes Security Team
|
||||
-----------------------
|
||||
|
||||
The Qubes Security Team can be contacted via email using the following address:
|
||||
The Qubes Security Team can be contacted via email at the following address:
|
||||
|
||||
~~~
|
||||
security at qubes-os dot org
|
||||
~~~
|
||||
security at qubes-os dot org
|
||||
|
||||
### Qubes Security Team GPG Key ###
|
||||
|
||||
Please use [this GPG key](https://keys.qubes-os.org/keys/qubes-os-security-team-key.asc) to encrypt any emails sent to this address. Like all GPG keys used by the Qubes project, this key is signed by the Qubes Master key. Please see [this page](/security/verifying-signatures/) for more information on how to verify the keys.
|
||||
### Security Team PGP Key ###
|
||||
|
||||
Please use the [Security Team PGP Key] to encrypt all emails sent to this address.
|
||||
This key is signed by the [Qubes Master Signing Key].
|
||||
Please see [Why and How to Verify Signatures] for information about how to verify these keys.
|
||||
|
||||
### Members of the Security Team ###
|
||||
|
||||
- Joanna Rutkowska \<joanna at invisiblethingslab dot com\>
|
||||
- Marek Marczykowski \<marmarek at invisiblethingslab dot com\>
|
||||
- [Joanna Rutkowska]
|
||||
- [Marek Marczykowski-Górecki]
|
||||
|
||||
|
||||
[Security FAQ]: /faq/#general--security
|
||||
[Security Goals]: /security/goals/
|
||||
[Security Pack]: /security/pack/
|
||||
[Security Bulletins]: /security/bulletins/
|
||||
[Canaries]: /security/canaries/
|
||||
[Xen Security Advisory (XSA) Tracker]: /security/xsa/
|
||||
[Why and How to Verify Signatures]: /security/verifying-signatures/
|
||||
[PGP Keys]: https://keys.qubes-os.org/keys/
|
||||
[Security Team PGP Key]: https://keys.qubes-os.org/keys/qubes-os-security-team-key.asc
|
||||
[Qubes Master Signing Key]: https://keys.qubes-os.org/keys/qubes-master-signing-key.asc
|
||||
[Joanna Rutkowska]: /team/#joanna-rutkowska
|
||||
[Marek Marczykowski-Górecki]: /team/#marek-marczykowski-górecki
|
||||
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue