Skip to content

Security: kernelkit/barebox

Security

SECURITY.md

Security Policy

Supported Versions

Please update to new barebox releases as they become available. Compatibility with old kernels is maintained over barebox releases.

The migration guides can be helpful in adapting configuration to new releases.

In addition, the barebox project currently maintains following long term stable (LTS) releases:

Reporting a Vulnerability

Please report security vulnerabilities to security@barebox.org. We will work with the reporter to create a fix and to coordinate the disclosure.

The threat model describes what barebox does and does not protect against and which classes of bugs are not vulnerabilities. Report those as ordinary bugs on the mailing list.

Securing barebox

Refer to the Security Considerations chapter of the documentation for information on how to configure barebox securely. That advice relies on the assumptions listed in the threat model.

There aren't any published security advisories