[PATCH 11/11] README, SECURITY.md: link the threat model and security considerations
Ahmad Fatoum
a.fatoum at pengutronix.de
Mon Sep 28 04:27:06 PDT 2026
From: Ahmad Fatoum <a.fatoum at barebox.org>
SECURITY.md says where to report vulnerabilities, but not what counts as
one. The README says nothing about security.
Link the new threat model from both files. In the README, add a short
Security section that also links the Security Considerations chapter.
Signed-off-by: Ahmad Fatoum <a.fatoum at barebox.org>
---
README.rst | 10 ++++++++++
SECURITY.md | 6 ++++++
2 files changed, 16 insertions(+)
diff --git a/README.rst b/README.rst
index fe783028dfad..1800f5e51822 100644
--- a/README.rst
+++ b/README.rst
@@ -284,6 +284,16 @@ are the release rules:
does never change, in order to make life easier for distribution
people.
+Security
+--------
+
+The `threat model <https://www.barebox.org/doc/latest/user/threat-model.html>`_
+describes what barebox does and does not protect against and which bugs are
+considered security vulnerabilities. The
+`Security Considerations <https://www.barebox.org/doc/latest/user/security.html>`_
+chapter describes how to configure barebox for verified boot. Refer to
+``SECURITY.md`` for how to report vulnerabilities.
+
.. _contributing:
Contributing
diff --git a/SECURITY.md b/SECURITY.md
index 862dd14623d9..39407514a361 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -19,7 +19,13 @@ releases:
Please report security vulnerabilities to security at barebox.org.
We will work with the reporter to create a fix and to coordinate the disclosure.
+The [threat model](https://www.barebox.org/doc/latest/user/threat-model.html)
+describes what barebox does and does not protect against and which classes of
+bugs are not vulnerabilities. Report those as ordinary bugs on the
+[mailing list](https://www.barebox.org/doc/latest/user/introduction.html#feedback).
+
## Securing barebox
Refer to the [Security Considerations](https://www.barebox.org/doc/latest/user/security.html)
chapter of the documentation for information on how to configure barebox securely.
+That advice relies on the assumptions listed in the threat model.
--
2.47.3
More information about the barebox
mailing list