Skip to content

Latest commit

 

History

History
65 lines (42 loc) · 3.78 KB

File metadata and controls

65 lines (42 loc) · 3.78 KB

Security Policy

We take the security of truestamp-cli seriously because this CLI is what users rely on to verify Truestamp proofs end to end. Any compromise of the binary or its verification logic directly undermines the cryptographic guarantees we offer.

Supported versions

Only the most recent published release is supported. The project maintains a single main branch with no maintenance or backport branches, so a security fix ships as a new release rather than as a patch to an older line. If you are running anything older than the latest release, upgrade before filing a report, since the issue may already be fixed.

The project is pre-1.0. Version numbers follow semantic versioning, but the supported surface is always just the newest release.

Reporting a vulnerability

Do not open a public GitHub issue for security reports.

Use one of these private channels instead:

  1. GitHub private vulnerability report (preferred). Open one at https://github.com/truestamp/truestamp-cli/security/advisories/new. Private vulnerability reporting is enabled on this repository. This keeps the conversation threaded with the repository and lets us assign a CVE if the issue warrants one.
  2. Email to security@truestamp.com. Please include "truestamp-cli" in the subject line.

Include, where possible:

  • The version (truestamp version output) and installation method (install.sh, Homebrew, go install, tarball).
  • A minimal proof of concept or reproduction steps.
  • The impact you believe a successful exploit would have.

What to expect

  • Acknowledgement within 3 business days.
  • Triage and preliminary assessment within 10 business days.
  • Coordinated disclosure window of up to 90 days from the first acknowledgement. We may ship a fix sooner and request an earlier public disclosure; we will not extend beyond 90 days without your agreement.
  • Credit in the release notes and, if you want, in a published advisory. Let us know how you would like to be named, or if you prefer to remain anonymous.

Scope

In scope:

Out of scope for this repository:

  • The Truestamp backend service at https://www.truestamp.com. Use the same private channels above to reach us, but note that the fix ships through a different pipeline and on a different timeline than a CLI release.
  • Third-party dependencies. Please report upstream first, and let us know so we can track the remediation here and pull in the fixed version.

Supply-chain verification

Every release publishes material you can check before trusting a binary:

  • checksums.txt with SHA-256 digests for every archive.
  • checksums.txt.sigstore, a keyless cosign bundle over that checksum file. Verify with cosign verify-blob --bundle.
  • An SBOM per archive, generated by syft (<archive>.sbom.json).
  • A GitHub build-provenance attestation over checksums.txt.

install.sh enforces the SHA-256 check by default, and additionally verifies the cosign bundle when cosign is on PATH. Set TRUESTAMP_REQUIRE_COSIGN=1 to make signature verification mandatory and fail the install when cosign is unavailable. TRUESTAMP_SKIP_CHECKSUM=1 disables verification entirely and exists for debugging only; never use it for a real install.