Skip to content

Latest commit

 

History

History
38 lines (27 loc) · 2.62 KB

security.md

File metadata and controls

38 lines (27 loc) · 2.62 KB
title layout permalink includeTOC
Scala Security Policy
inner-page-no-masthead
/security/
false

Receiving Security Announcements

Security announcements related to Scala are published to the "Security Announcements" channel on our discourse forum.

Messages to this channel can only be posted by administrators, so it is very low traffic. To set up email notifications for new security announcements, read this post.

Releases Integrity

To ensure the integrity of all the releases, our organization uses PGP keys for cryptographic signing. We provide below an exhaustive list of all the keys used for signing the artifacts under the org.scala-lang namespace on Maven Central

Fingerprint Algorithm Public Key
86DA 41A5 E169 9C9C EBE9 64A8 A905 2B1B 6D92 E560 RSA-4096 Download Public Key
ACF3 9CCD ED38 E2C6 F089 8BF2 8F7F 6C04 5196 7B84 RSA-4096 Download Public Key
2A5E 8B33 8438 CAC7 033F 9D8F B8A0 45C0 A6EC 398E RSA-4096 Download Public Key

Reporting Vulnerabilities

We strongly encourage reporting security issues in Scala to us privately before disclosing them in public.

The email address for security related communication is [email protected]. Messages are delivered to the Scala Security Team, which includes people from EPFL, the Scala Center, VirtusLab and Lightbend.

We strive to acknowledge reports within 2 business days. In case you don't receive a reply within a few days and would like to escalate, our advice is to ask for a contact person in a forum hosted by the Scala organization: