Browse Source

add release signing key / security contact to README, fixes #1560

Thomas Waldmann 8 years ago
parent
commit
2e1cf17dd5
1 changed files with 16 additions and 0 deletions
  1. 16 0
      README.rst

+ 16 - 0
README.rst

@@ -114,6 +114,22 @@ Now doing another backup, just to show off the great deduplication:
 
 For a graphical frontend refer to our complementary project `BorgWeb <https://borgweb.readthedocs.io/>`_.
 
+Checking Release Authenticity and Security Contact
+==================================================
+
+`Releases <https://github.com/borgbackup/borg/releases>`_ are signed with this GPG key,
+please use GPG to verify their authenticity.
+
+In case you discover a security issue, please use this contact for reporting it privately
+and please, if possible, use encrypted E-Mail:
+
+Thomas Waldmann <tw@waldmann-edv.de>
+
+GPG Key Fingerprint: 6D5B EF9A DD20 7580 5747  B70F 9F88 FB52 FAF7 B393
+
+The public key can be fetched from any GPG keyserver, but be careful: you must
+use the **full fingerprint** to check that you got the correct key.
+
 Links
 =====