Open guydc opened 8 months ago
This issue has been automatically marked as stale because it has not had activity in the last 30 days.
This issue has been automatically marked as stale because it has not had activity in the last 30 days.
This issue has been automatically marked as stale because it has not had activity in the last 30 days.
Description: Projects like Envoy proxy have a robust processe for vulnerability management, outlined here. OSS control planes like Istio have similar processes in place.
Envoy Gateway should establish similar processes, communication channels, responsibilities, SLOs, etc.
More concretely, the following should be done:
Additionally, Envoy Gateway security representatives should strive to join the Envoy Proxy private distributor list, to ensure early disclosure of vulnerabilities and proper preparation for fix releases.