From 0a7d7f6e581420c9155140afa9771e3b144ab509 Mon Sep 17 00:00:00 2001 From: Paul Warren Date: Thu, 25 Jan 2024 09:01:21 -0800 Subject: [PATCH 1/2] Add draft RFC for establishing CFF as a CVE Numbering Authority --- .../rfc-draft-cff-cve-numbering-authority.md | 22 +++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 toc/rfc/rfc-draft-cff-cve-numbering-authority.md diff --git a/toc/rfc/rfc-draft-cff-cve-numbering-authority.md b/toc/rfc/rfc-draft-cff-cve-numbering-authority.md new file mode 100644 index 00000000..db0b4916 --- /dev/null +++ b/toc/rfc/rfc-draft-cff-cve-numbering-authority.md @@ -0,0 +1,22 @@ +# Meta +[meta]: #meta +- Name: CFF CVE Numbering Authority +- Start Date: 2024-01-25 +- Author(s): paulcwarren +- Status: Draft +- RFC Pull Request: (fill in with PR link after you submit it) + + +## Summary + +For the last several years the CFF has relied on sponsoring member VMWare as the CVE numbering authority. When we have needed to publish a CVE, we claim a CVE number from their reservation block. + +This responsibility should lie with the foundation itself. + +## Problem + +CVE must be published in a timely fashion. Any interruptions in the allocation of a CVE number, pre-disclosure or disclosure puts installations and their Users are at risk. + +## Proposal + +Establish Cloud Foundry Foundation as a CVE Numbering Authority managing its own block of CVE numbers. \ No newline at end of file From 65d1415dd28aec6908afe0bf352cecf22833cbcc Mon Sep 17 00:00:00 2001 From: Paul Warren Date: Thu, 25 Jan 2024 09:02:50 -0800 Subject: [PATCH 2/2] Update RFC with PR link --- toc/rfc/rfc-draft-cff-cve-numbering-authority.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/toc/rfc/rfc-draft-cff-cve-numbering-authority.md b/toc/rfc/rfc-draft-cff-cve-numbering-authority.md index db0b4916..02a7af4d 100644 --- a/toc/rfc/rfc-draft-cff-cve-numbering-authority.md +++ b/toc/rfc/rfc-draft-cff-cve-numbering-authority.md @@ -4,7 +4,7 @@ - Start Date: 2024-01-25 - Author(s): paulcwarren - Status: Draft -- RFC Pull Request: (fill in with PR link after you submit it) +- RFC Pull Request: https://github.com/cloudfoundry/community/pull/762 ## Summary