xref: /optee_os/lib/libmbedtls/mbedtls/SECURITY.md (revision 7901324d9530594155991c8b283023d567741cc7)
1*7901324dSJerome Forissier## Reporting Vulneratibilities
2*7901324dSJerome Forissier
3*7901324dSJerome ForissierIf you think you have found an Mbed TLS security vulnerability, then please
4*7901324dSJerome Forissiersend an email to the security team at
5*7901324dSJerome Forissier<mbed-tls-security@lists.trustedfirmware.org>.
6*7901324dSJerome Forissier
7*7901324dSJerome Forissier## Security Incident Handling Process
8*7901324dSJerome Forissier
9*7901324dSJerome ForissierOur security process is detailled in our
10*7901324dSJerome Forissier[security
11*7901324dSJerome Forissiercenter](https://developer.trustedfirmware.org/w/mbed-tls/security-center/).
12*7901324dSJerome Forissier
13*7901324dSJerome ForissierIts primary goal is to ensure fixes are ready to be deployed when the issue
14*7901324dSJerome Forissiergoes public.
15*7901324dSJerome Forissier
16*7901324dSJerome Forissier## Maintained branches
17*7901324dSJerome Forissier
18*7901324dSJerome ForissierOnly the maintained branches, as listed in [`BRANCHES.md`](BRANCHES.md),
19*7901324dSJerome Forissierget security fixes.
20*7901324dSJerome ForissierUsers are urged to always use the latest version of a maintained branch.
21