Security Advisories

Security advisories for downpipes, and what happens if we revoke our update-signing key.

Public Last updated 29 September 2026

This page lists the security advisories we publish for downpipes. It states our promise to notify customers of a compromise. The last section tells you what happens if we revoke our update-signing key.

Published advisories

No security advisories have been published.

How we publish an advisory

We publish advisories on this page and in its RSS feed.

To report a vulnerability to us, follow our Vulnerability Disclosure Policy.

When we notify you of a compromise

We notify customers within 72 hours if the keys that sign our releases and our update channel, a release, or our control plane is compromised.

The 72 hours start when we become aware of the compromise. Our control plane is the service that issues downpipes licences.

We email the licensee contact on record, and we post the notice on this page and in its RSS feed.

If we revoke our update-signing key

If we ever revoke our update-signing key, we contact each licensee directly and guide them through the change.


Document Information

  • Version. 1.0
  • Last Updated. 2026-09-29
  • Owner. ISMS Owner
  • Review Frequency. Annually
  • Classification. Public
  • Change (1.0). First publication.