We encourage security researchers and members of the community to report vulnerabilities to us.
Are you a project maintainer coordinating a disclosure with us? See the Maintainer Process page for step-by-step guidance.
Report a Vulnerability
Use the report form. It reaches the Points of Contact directly, asks for what we need up front, and gives your report a tracked case from the start. The form requires a sign-in with GitHub or Hex.pm so we can reach you about the report.
If you would rather not sign in, or the form is unavailable, email works as a backup:
- Email: cna@erlef.org
- GPG Key: for encrypted communications
Fingerprint: 38BD 201B 397E 28F1 F3D9 3EC7 6E03 1A81 1F26 6E21
Team
@IngelaAndin— Ingela Andin, OTP Core Contributor — Primary PoC@maennchen— Jonatan Männchen, CISO, EEF — Primary PoC@voltone— Bram Verburg, Security WG Chair — Primary PoC@ericmj— Eric Meadows-Jönsson, Hex.pm Core Maintainer@pjullrich— Peter Ullrich, Ecosystem Security Researcher
Questions & Suggestions
For general questions, use GitHub Discussions.
Note: GitHub Discussions are public. Never report or include vulnerability details there.