Please do not open a public GitHub issue for security problems.
Instead, report vulnerabilities privately:
- Prefer GitHub Private Vulnerability Reporting: go to the relevant repo → Security → Report a vulnerability. (Enable it on the repo if missing.)
- Or email security@zurvanlinux.org. If you can, encrypt with the Zurvan Linux archive GPG key published at https://repo.zurvanlinux.org/public.key (fingerprint in the same key). The P0 GPG key is generated offline; until it is published, email is the fallback channel.
Please include:
- Affected component/repo and version (ISO tag, package version, or commit SHA).
- A clear description and proof of concept or reproduction steps.
- Your assessment of impact and any suggested remediation.
- Acknowledgement: within 3 business days.
- Initial assessment and a coordination plan: within 7 business days.
- Coordinated disclosure after a fix is available (or after 90 days, per standard responsible-disclosure convention, whichever comes first).
In scope: the installed system (kernel/driver/firmware configuration shipped by
the ISO), the APT repository integrity (Release/InRelease signing), the
Calamares configuration, the zurvan-dns-bypass mechanism, the welcome app, and
the website. Out of scope: vulnerabilities in upstream Debian/KDE/Flatpak
packages themselves — report those to the upstream project or Debian's security
team.
The custom APT repository is signed by a 4096-bit GPG key whose primary is held
offline; only a signing subkey is used in CI. See
apt-repository/README.md
for the rotation runbook. If you suspect the signing subkey has been compromised,
report it immediately via the channels above so the subkey can be revoked.