open-telemetry / sig-security

Apache License 2.0
7 stars 9 forks source link

Create CVEE disclosure on OTel website #8

Closed cartersocha closed 2 months ago

cartersocha commented 1 year ago

Copy CVEE disclosure from kubernetes and start public incident discloure

jpkrohling commented 2 months ago

@cartersocha, is this what you had in mind? https://kubernetes.io/docs/reference/issues-security/official-cve-feed/

jpkrohling commented 2 months ago

From that page, I eventually landed here, which has many things we could use as base as well: https://github.com/kubernetes/committee-security-response/tree/main

cartersocha commented 2 months ago

We already implemented this. Good to go