Vulnerability disclosure · OpenPGP

Report a vulnerability

Report security issues in the Bobine software, website or APT repository privately. Encrypt your report with the key below and check its fingerprint on at least two channels before sending.

Reports open Ed25519 + Curve25519 Key expires 2028-10-06 security.txt signed (RFC 9116)

3-Step Private Report

1.

Retrieve and verify the key

Fetch the public key, then compare the fingerprint with the table below and with the copy published in the GitHub repository:

Terminal (Bash)
gpg --locate-keys security@bobine.fit && gpg --fingerprint security@bobine.fit
2.

Encrypt your report

Encrypt the report for the security key. To receive an encrypted reply, attach your own public key:

Terminal (Bash)
gpg --armor --encrypt --recipient security@bobine.fit report.txt
3.

Send it

Send the encrypted file (report.txt.asc) to the security address, or open a private report on GitHub:

E-mail
security@bobine.fit

Key & Disclosure Details

Identity Bobine Security <security@bobine.fit>
Fingerprint 23CA D324 C507 FB0F 97E6 AECA 6E4C 020E F8BD FEB2
Algorithms Ed25519 (certify, sign) · Curve25519 (encrypt)
Expires 2028-10-06
Raw Public Key security.asc
security.txt (signed) /.well-known/security.txt
DNS TXT openpgp4fpr on bobine.fit · OPENPGPKEY record (RFC 7929)
Policy bobine.fit/securite · SECURITY.md
Revoked key 8208 FFD3 F7AB 4DD3 (revoked 2026-10-07)