Sitelet https://github.com/upsetdev/edns/security
Skip to content

Security: upsetdev/edns

Security

SECURITY.md

Security Policy

Supported versions

Only the latest commit on main, which is what runs at edns.upset.dev, receives security fixes.

Reporting a vulnerability

Please do not open a public issue for security problems.

Report them privately through GitHub's private vulnerability reporting for this repository. Include:

  • a description of the issue and its impact,
  • steps or a proof of concept to reproduce it,
  • any suggested fix, if you have one.

You can expect an acknowledgement within a few days. Please give us reasonable time to release a fix before disclosing the issue publicly.

Scope

In scope: the code in this repository and the service at edns.upset.dev, for example cache poisoning, ACME challenge manipulation, token prediction or leakage, and denial of service through a single cheap request.

Out of scope: volumetric DDoS, and reports that only show that the service reveals your resolver's IP or ECS subnet to you, since that is what it is for.

There aren't any published security advisories