Security & Vulnerability Disclosure
1. Commitment to Security
TelcoSec is dedicated to maintaining the highest security posture for telecommunications software. Every package in this repository is cryptographically signed with our 4096-bit RSA release key.
2. Responsible Vulnerability Disclosure
If you discover a security vulnerability in our repository infrastructure or applications, we appreciate your cooperation in disclosing it to us responsibly before public release:
- Security Email:
security@telcosec.net - PGP Key Fingerprint:
146D E2BB FE45 4A0E 8A9D E112 3589 C4DE FA56 8899 - Standard Security Location:
/.well-known/security.txt
3. Disclosure Guidelines
- Provide detailed steps to reproduce the vulnerability with a proof-of-concept where possible.
- Allow us reasonable time to patch the issue before making any public disclosure.
- Do not exploit the vulnerability beyond what is strictly necessary to demonstrate proof-of-concept.
4. Hall of Fame
We gratefully acknowledge researchers who report security issues in accordance with our responsible disclosure guidelines.