Skip to content

Security

Winni Neessen edited this page Oct 3, 2024 · 2 revisions

Table of contents

Philosophy

Security is high on the priority list for go-mail. We don't claim to be free of bugs, but we do provide automated tests various security aspects. Of course logic bugs can always exist. If you find any security issues, please report it.

Reporting a vulnerability

To report (possible) security issues in go-mail, please either send a mail to security@go-mail.dev or use Github's private reporting feature. Reports are always welcome. Even if you are not 100% certain that a specific issue you found counts as a security issue, we'd love to hear the details, so we can figure out together if the issue in question needds to be addressed.

Typically, you will receive an answer within a day (depending on the day/time, you might even hear back within a few hours).

Encryption

You can send OpenPGP/GPG encrpyted mails to the security@go-mail.dev address.

OpenPGP/GPG public key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
xjMEY8RwPBYJKwYBBAHaRw8BAQdAiLsW7pv+CCMq5Ol0hbIB1HnJI97u3zJw
Wslr7GJzgOzNK3NlY3VyaXR5QGdvLW1haWwuZGV2IDxzZWN1cml0eUBnby1t
YWlsLmRldj7CjAQQFgoAPgUCY8RwPAQLCQcICRCgTBOxf8keAAMVCAoEFgAC
AQIZAQIbAwIeARYhBAoWEB7Y0bE7zcIOuaBME7F/yR4AAAByugD9HabWXsyD
aPIDrIS97OBA1OLltB4NPT5ba9whKRxTEmMBALBiB2ML4ZTrjLqI6UbGkhJq
mWeMtvmU0chZT7WNBO0PzjgEY8RwPBIKKwYBBAGXVQEFAQEHQGDEccz6gvl5
t8cMMb/Dy2l0elRZL+Nd0gOhnbWMWlArAwEIB8J4BBgWCAAqBQJjxHA8CRCg
TBOxf8keAAIbDBYhBAoWEB7Y0bE7zcIOuaBME7F/yR4AAADaMwD9EvEA3NSN
NtdSaeL/euh6oRRiCjKzh5bIqZiQXqMlIOoBAJvPE2facs8MISwTtDoHW0sD
WdOs3yBpGlGCs5WEqvQH
=zn96
-----END PGP PUBLIC KEY BLOCK-----

Known vulnerabilities

Even though there is no known security vulnerability in go-mail, you can always check the security advisories page of our GitHub project.