Skip to content

Security: ZurvanLinux/iso-builder

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please do not open a public GitHub issue for security problems.

Instead, report vulnerabilities privately:

  1. Prefer GitHub Private Vulnerability Reporting: go to the relevant repo → SecurityReport a vulnerability. (Enable it on the repo if missing.)
  2. Or email security@zurvanlinux.org. If you can, encrypt with the Zurvan Linux archive GPG key published at https://repo.zurvanlinux.org/public.key (fingerprint in the same key). The P0 GPG key is generated offline; until it is published, email is the fallback channel.

Please include:

  • Affected component/repo and version (ISO tag, package version, or commit SHA).
  • A clear description and proof of concept or reproduction steps.
  • Your assessment of impact and any suggested remediation.

Response targets (best-effort, Phase 1)

  • Acknowledgement: within 3 business days.
  • Initial assessment and a coordination plan: within 7 business days.
  • Coordinated disclosure after a fix is available (or after 90 days, per standard responsible-disclosure convention, whichever comes first).

Scope

In scope: the installed system (kernel/driver/firmware configuration shipped by the ISO), the APT repository integrity (Release/InRelease signing), the Calamares configuration, the zurvan-dns-bypass mechanism, the welcome app, and the website. Out of scope: vulnerabilities in upstream Debian/KDE/Flatpak packages themselves — report those to the upstream project or Debian's security team.

Signing key integrity

The custom APT repository is signed by a 4096-bit GPG key whose primary is held offline; only a signing subkey is used in CI. See apt-repository/README.md for the rotation runbook. If you suspect the signing subkey has been compromised, report it immediately via the channels above so the subkey can be revoked.

There aren't any published security advisories