Add SECURITY.md with AWS-LC threat model - #3421
Open
WesleyRosenblum wants to merge 8 commits into
Open
Conversation
AWS-LC has no repo-level security policy, so github.com/aws/aws-lc/security/policy falls back to the aws/.github org default. That default is reporting boilerplate with no threat model, so reporters have no stated basis for deciding what is in scope. Add a SECURITY.md adapted from the s2n-tls security policy, keeping its section order and the shared AWS reporting language. The threat model is rewritten for a cryptographic library: implementation defects are framed for C, and timing and cache-based side channels are in scope rather than out, since constant-time behavior is a core promise of libcrypto. Link the policy from README and CONTRIBUTING, both of which carry a security reporting section.
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:51 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:52 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:52 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:52 — with
GitHub Actions
Error
WesleyRosenblum
requested a deployment
to
manual-approval
August 11, 2026 21:52 — with
GitHub Actions
Waiting
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:52 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:52 — with
GitHub Actions
Error
WesleyRosenblum
marked this pull request as draft
August 11, 2026 21:53
Naming downstream consumers does no work in a shared responsibility model, which is about which party is responsible for what rather than who depends on the library. Removing it also drops the only claim in the document that could not be verified from this repo's own source.
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:59 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:59 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:59 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:59 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:59 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:59 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 21:59 — with
GitHub Actions
Error
The clause restated the Vulnerability Scope bullet on failures reported as success without adding anything, and it broke the parallelism of a sentence whose other items are affirmative capability promises. The Vulnerability Scope bullet is the operative statement, since it tells a reporter what to report.
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:04 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:04 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:04 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:04 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:04 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:04 — with
GitHub Actions
Error
WesleyRosenblum
requested a deployment
to
manual-approval
August 11, 2026 22:04 — with
GitHub Actions
Waiting
Zeroization and constant-time behavior are mechanisms for discharging a duty, not the duty itself, and both are already listed as reportable issues under Vulnerability Scope. Mixing them into the responsibility statement put two abstraction levels in one sentence and duplicated the scope list. State the duty instead, matching the register s2n-tls uses in the same slot.
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:08 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:09 — with
GitHub Actions
Error
The sentence explained why AWS-LC is easy to misuse instead of stating whose duty it is, and compared the library unfavourably to an unnamed alternative. Declining to promise misuse resistance is expressed by not promising it and by the Vulnerability Scope carve-outs for invalid arguments, deprecated compatibility APIs, and caller-selected algorithms, all of which remain.
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:17 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:18 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:18 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:18 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:18 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:18 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 11, 2026 22:18 — with
GitHub Actions
Error
WesleyRosenblum
marked this pull request as ready for review
August 11, 2026 22:27
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3421 +/- ##
==========================================
- Coverage 78.43% 78.24% -0.20%
==========================================
Files 696 698 +2
Lines 124514 124591 +77
Branches 17285 17289 +4
==========================================
- Hits 97662 97484 -178
- Misses 25925 26182 +257
+ Partials 927 925 -2 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
WesleyRosenblum
had a problem deploying
to
manual-approval
August 12, 2026 20:55 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 12, 2026 20:55 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 12, 2026 20:55 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 12, 2026 20:55 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 12, 2026 20:55 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 12, 2026 20:55 — with
GitHub Actions
Error
WesleyRosenblum
had a problem deploying
to
manual-approval
August 12, 2026 20:55 — with
GitHub Actions
Error
justsmth
reviewed
Aug 19, 2026
WesleyRosenblum
requested a deployment
to
manual-approval
August 20, 2026 18:09 — with
GitHub Actions
Waiting
WesleyRosenblum
requested a deployment
to
manual-approval
August 20, 2026 18:09 — with
GitHub Actions
Waiting
WesleyRosenblum
requested a deployment
to
manual-approval
August 20, 2026 18:09 — with
GitHub Actions
Waiting
WesleyRosenblum
requested a deployment
to
manual-approval
August 20, 2026 18:09 — with
GitHub Actions
Waiting
WesleyRosenblum
requested a deployment
to
manual-approval
August 20, 2026 18:09 — with
GitHub Actions
Waiting
WesleyRosenblum
requested a deployment
to
manual-approval
August 20, 2026 18:09 — with
GitHub Actions
Waiting
WesleyRosenblum
temporarily deployed
to
manual-approval
August 20, 2026 18:10 — with
GitHub Actions
Inactive
justsmth
approved these changes
Aug 20, 2026
Contributor
|
🔒 Security Review — View Report Please review before merging. |
geedo0
approved these changes
Aug 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of changes:
Adds a
SECURITY.mdin the same vein as s2n-tls and s2n-quic, following their section structure and reusing the shared AWS reporting language.Also links the policy from
README.mdandCONTRIBUTING.md, both of which carry a security reporting section.Testing:
Docs-only.
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license and the ISC license.