Canonical · Vulnerability Disclosure
Canonical Vulnerability Disclosure
Vulnerability disclosure
Canonical publishes a named, dated vulnerability disclosure and embargo policy covering Ubuntu, Canonical-authored software (LXD, MAAS, Juju, snapd, Snapcraft, Landscape, Launchpad, Mir) and Canonical-owned and -managed infrastructure. It is one of the more complete disclosure programs in the catalog: it names the reporting channels, publishes a PGP key for encrypted submissions, and states the embargo expectations on both sides.
Canonical runs a coordinated vulnerability disclosure program on Hackerone.
CloudLinuxOpen-SourceUbuntuContainersBare MetalCharmsIdentity
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.