[PATCH 11/11] README, SECURITY.md: link the threat model and security considerations

Ahmad Fatoum a.fatoum at pengutronix.de
Mon Sep 28 04:27:06 PDT 2026


From: Ahmad Fatoum <a.fatoum at barebox.org>

SECURITY.md says where to report vulnerabilities, but not what counts as
one. The README says nothing about security.

Link the new threat model from both files. In the README, add a short
Security section that also links the Security Considerations chapter.

Signed-off-by: Ahmad Fatoum <a.fatoum at barebox.org>
---
 README.rst  | 10 ++++++++++
 SECURITY.md |  6 ++++++
 2 files changed, 16 insertions(+)

diff --git a/README.rst b/README.rst
index fe783028dfad..1800f5e51822 100644
--- a/README.rst
+++ b/README.rst
@@ -284,6 +284,16 @@ are the release rules:
   does never change, in order to make life easier for distribution
   people.
 
+Security
+--------
+
+The `threat model <https://www.barebox.org/doc/latest/user/threat-model.html>`_
+describes what barebox does and does not protect against and which bugs are
+considered security vulnerabilities. The
+`Security Considerations <https://www.barebox.org/doc/latest/user/security.html>`_
+chapter describes how to configure barebox for verified boot. Refer to
+``SECURITY.md`` for how to report vulnerabilities.
+
 .. _contributing:
 
 Contributing
diff --git a/SECURITY.md b/SECURITY.md
index 862dd14623d9..39407514a361 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -19,7 +19,13 @@ releases:
 Please report security vulnerabilities to security at barebox.org.
 We will work with the reporter to create a fix and to coordinate the disclosure.
 
+The [threat model](https://www.barebox.org/doc/latest/user/threat-model.html)
+describes what barebox does and does not protect against and which classes of
+bugs are not vulnerabilities. Report those as ordinary bugs on the
+[mailing list](https://www.barebox.org/doc/latest/user/introduction.html#feedback).
+
 ## Securing barebox
 
 Refer to the [Security Considerations](https://www.barebox.org/doc/latest/user/security.html)
 chapter of the documentation for information on how to configure barebox securely.
+That advice relies on the assumptions listed in the threat model.
-- 
2.47.3




More information about the barebox mailing list