Added a security section
See https://github.com/ipfs/community/issues/62 License: MIT Signed-off-by: Richard Littauer <richard.littauer@gmail.com>
Richard Littauer committed
Nov 2, 2015 at 05:25 UTC
cdcf457d8fd7df5258de7e436b2a664a7b07bcec
1 file changed
+8
README.md
+8
@@ -12,6 +12,14 @@ Please put all issues regarding IPFS _design_ in the
12
[ipfs repo issues](https://github.com/ipfs/ipfs/issues).
13
Please put all issues regarding go IPFS _implementation_ in [this repo](https://github.com/ipfs/go-ipfs/issues).
14
15
+## Security Issues
16
+
17
+The IPFS protocol and its implementations are still in heavy development. This means that there may be problems in our protocols, or there may be mistakes in our implementations. And -- though IPFS is not production-ready yet -- many people are already running nodes in their machines. So we take security vulnerabilities very seriously. If you discover a security issue, please bring it to our attention right away!
18
+
19
+If you find a vulnerability that may affect live deployments -- for example, by exposing a remote execution exploit -- please send your report privately to security@ipfs.io. Please DO NOT file a public issue.
20
+
21
+If the issue is a protocol weakness that cannot be immediately exploited or something not yet deployed, just discuss it openly.
22
+
23
## Install
24
25
The canonical download instructions for IPFS are over at: http://ipfs.io/docs/install