l3af-project / governance

L3AF Project Governance Documents
Creative Commons Zero v1.0 Universal
0 stars 3 forks source link

Security vulnerability reporting process #4

Open dthaler opened 2 years ago

dthaler commented 2 years ago

We need to document what the inbound and outbound vulnerability management process is.

There is work in progress linked at bottom of https://github.com/ossf/wg-vulnerability-disclosures

dthaler commented 2 years ago

Another comparable:

vmbrasseur commented 2 years ago

I was looking into this and think it's something that we ought to be following the LFN policy for. Unfortunately, I can't locate an LFN security vulnerability disclosure policy.

@lilluzzi, could you please lend a hand here?

lilluzzi commented 2 years ago

@vmbrasseur LFN policy is to use LFx Security (see link above). Projects will be onboarding in the coming weeks. The security team is working on the rollout plan to communities.

vmbrasseur commented 2 years ago

@lilluzzi That's for scanning for vulnerabilities though, not reporting them, isn't it?

For instance, here's the template for a policy for the projects under CCC: security-response-policies.md

Does LFN have a policy for vulnerability disclosure for its projects?