openssl / technical-policies

Mirror of the repository for technical policies, governed by the OTC (OpenSSL Technical Committee)
20 stars 32 forks source link

Security advisories #87

Open kroeckx opened 8 months ago

kroeckx commented 8 months ago

I think we need to have a document describing what should all be covered in a security advisory. We've talked about this several times in the past, but I can't actually find an open issue for it.

Some of the things we should consider:

ghost commented 6 months ago

After F2F

kroeckx commented 3 days ago

It should include details on how people can check that their code is affected or not. This might include things like affected functions, so they can search there code to see if they're affected or not.

kroeckx commented 3 days ago

Other useful information to add is which commit (per branch) introduced the problem.