jamulussoftware / jamulussoftware/jamulus
Security: Generate and document GPG key(s)
- Dominant language
- C
- Stars
- 1.1k
- Forks
- 248
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 9
Description
**Has this feature been discussed and generally agreed?**
jamulussoftware/jamuluswebsite#319 was about documenting the process and a contact address for reporting security issues. It was also discussed to provide a way to contact the project in encrypted form. This still needs to be done.
I'm opening this on the code repo as this is where `SECURITY.md` lives and will have to be updated.
**Describe the solution you'd like**
Variants:
1. Document each developer's own GPG key (and address) on their team page (tbd)
2. Generate a key for team@ and share it.
Both variants have advantages and disadvantages, see https://github.com/jamulussoftware/jamuluswebsite/issues/319#issuecomment-803663521 and later comments.
Contributor guide
Assessment
This issue has not been assessed yet.