Qubes OS Project Security Center
- Security FAQ
- Security Goals
- Security Pack
- Security Bulletins
- Xen Security Advisory (XSA) Tracker
- Why and How to Verify Signatures
- PGP Keys
Reporting Security Issues in Qubes OS
If you believe you have found a security issue affecting Qubes OS, either directly or indirectly (e.g. the issue affects Xen in a configuration that is used in Qubes OS), then we would be more than happy to hear from you!
We promise to treat any reported issue seriously and, if the investigation confirms it affects Qubes, to patch it within a reasonable time, release a public Security Bulletin that describes the issue, discuss potential impact of the vulnerability, reference applicable patches or workarounds, and credit the discoverer.
The list of all Qubes Security Advisories published so far can be found here.
The Qubes Security Team
The Qubes Security Team can be contacted via email using the following address:
security at qubes-os dot org
Qubes Security Team GPG Key
Please use this GPG key to encrypt any emails sent to this address. Like all GPG keys used by the Qubes project, this key is signed by the Qubes Master key. Please see this page for more information on how to verify the keys.
Members of the Security Team
- Joanna Rutkowska <joanna at invisiblethingslab dot com>
- Marek Marczykowski <marmarek at invisiblethingslab dot com>