1 Reporting security issues
3 We care deeply about providing a secure Ruby environment for running your code.
4 If you find a security issue, please send an email to security@rubini.us. In
5 order to keep your message safe, you can use our public key to send the report
8 The public key can be found in the Rubinius repository under security.pub in
9 the top level directory, on the website at http://rubini.us/security.pub, and
10 in the MIT PGP database at:
12 http://pgp.mit.edu:11371/pks/lookup?op=vindex&search=0x0F7D2F9537F9880C.
14 We will do our best to respond to you within 72 hours and will work with you
15 to create a fix for the issue. Sending an email to security@rubini.us will not
16 result in a public disclosure. We will work with you for on a public disclosure
17 after we have a fix ready.
19 For security issues for extensions that are copies from CRuby, please report
20 them there directly. The instructions can be found at http://www.ruby-lang.org/en/security/.
21 We track those issues as well and are informed by their security team. This
22 makes sure Rubinius also gets updated with these security fixes.