# Security Policy
## Reporting a Vulnerability
If you find any vulnerability in this project,
don't hesitate to _report them_.
1. Use any of the [private contact addresses](https://github.com/qubip/aurora#support).
2. Describe the vulnerability.
If you have a fix, that is most welcome -- please attach or summarize
it in your message!
3. We will evaluate the vulnerability and, if necessary, release a fix
or mitigating steps to address it.
We will contact you to let you know the outcome, and will credit you
in the report.
Please **do not disclose the vulnerability publicly** until a fix is
released!
4. Once we have either
a) published a fix, or
b) declined to address the vulnerability for whatever reason,
you are free to publicly disclose it.
## GPG keys
### `security@romen.dev`
- Key ID: `0xF2C6707B23AD7E39`
- Fingerprint: `F628 7C98 A405 3CC0 8BCC F129 F2C6 707B 23AD 7E39`
- [Download](./keys/security_romen_dev.asc)
### `coc@romen.dev`
- Key ID: `0xDDE6AE69A49F648A`
- Fingerprint: `4022 B158 B9EF 85FA A8C0 B675 DDE6 AE69 A49F 648A`
- [Download](./keys/coc_romen_dev.asc)