openssl / technical-policies

Mirror of the repository for technical policies, governed by the OTC (OpenSSL Technical Committee)
23 stars 34 forks source link

Security advisories #87

Open kroeckx opened 10 months ago

kroeckx commented 10 months ago

I think we need to have a document describing what should all be covered in a security advisory. We've talked about this several times in the past, but I can't actually find an open issue for it.

Some of the things we should consider:

ghost commented 9 months ago

After F2F

kroeckx commented 2 months ago

It should include details on how people can check that their code is affected or not. This might include things like affected functions, so they can search there code to see if they're affected or not.

kroeckx commented 2 months ago

Other useful information to add is which commit (per branch) introduced the problem.