Skip to content

Vulnerability Disclosure #322

@juanis2112

Description

@juanis2112

We are doing some work at the summit on security best practices and vulnerability disclosure came up. So we'll add it as SPEC 11. Here's the scope for the spec:

  • Securicy policy (What should include and template)

    • Prominently document how to report vulnerabilities
    • Contact information
  • Enable private vulnerability reporting via API (GitHub Security Advisories for GitHub, Confidential Issues for GitLab)

  • What to do when you get a vulnerability report?

    • Use resources like the Guide to coordinated vulnerability disclosure.
    • Explicitly disclose security issues affecting vendored dependencies.
    1. acknowledge
    2. request cve
    3. share cve
    4. release (add cve number in the release notes)

This is the draft: https://hackmd.io/dZiPH2UDRXWtPg_-1af2Iw

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions