diff --git a/doc/grpc_security_audit.pdf b/doc/grpc_security_audit.pdf new file mode 100644 index 00000000000..fe0219f7b92 Binary files /dev/null and b/doc/grpc_security_audit.pdf differ diff --git a/doc/security_audit.md b/doc/security_audit.md new file mode 100644 index 00000000000..f8a84a127d1 --- /dev/null +++ b/doc/security_audit.md @@ -0,0 +1,4 @@ +# gRPC Security Audit + +A third-party security audit of gRPC C++ stack was performed by [Cure53](https://cure53.de) in October 2019. The full report can be found [here](https://github.com/grpc/grpc/tree/master/doc/grpc_security_audit.pdf). The medium severity issue (GRP-01-001) identified in this report was fixed in version 1.24.0 and above. The fix was also patched in version 1.23.1. + diff --git a/tools/doxygen/Doxyfile.c++ b/tools/doxygen/Doxyfile.c++ index 6ac313ad135..344a705137e 100644 --- a/tools/doxygen/Doxyfile.c++ +++ b/tools/doxygen/Doxyfile.c++ @@ -786,6 +786,7 @@ doc/interop-test-descriptions.md \ doc/keepalive.md \ doc/load-balancing.md \ doc/naming.md \ +doc/security_audit.md \ doc/server-reflection.md \ doc/server_reflection_tutorial.md \ doc/server_side_auth.md \ diff --git a/tools/doxygen/Doxyfile.c++.internal b/tools/doxygen/Doxyfile.c++.internal index 80ed64984b6..71cdff42584 100644 --- a/tools/doxygen/Doxyfile.c++.internal +++ b/tools/doxygen/Doxyfile.c++.internal @@ -786,6 +786,7 @@ doc/interop-test-descriptions.md \ doc/keepalive.md \ doc/load-balancing.md \ doc/naming.md \ +doc/security_audit.md \ doc/server-reflection.md \ doc/server_reflection_tutorial.md \ doc/server_side_auth.md \ diff --git a/tools/doxygen/Doxyfile.core b/tools/doxygen/Doxyfile.core index f4533f240bd..26a9e925e22 100644 --- a/tools/doxygen/Doxyfile.core +++ b/tools/doxygen/Doxyfile.core @@ -793,6 +793,7 @@ doc/interop-test-descriptions.md \ doc/keepalive.md \ doc/load-balancing.md \ doc/naming.md \ +doc/security_audit.md \ doc/server-reflection.md \ doc/server_reflection_tutorial.md \ doc/server_side_auth.md \ diff --git a/tools/doxygen/Doxyfile.core.internal b/tools/doxygen/Doxyfile.core.internal index de3f8640e9a..b91da524fa2 100644 --- a/tools/doxygen/Doxyfile.core.internal +++ b/tools/doxygen/Doxyfile.core.internal @@ -793,6 +793,7 @@ doc/interop-test-descriptions.md \ doc/keepalive.md \ doc/load-balancing.md \ doc/naming.md \ +doc/security_audit.md \ doc/server-reflection.md \ doc/server_reflection_tutorial.md \ doc/server_side_auth.md \