ossf / wg-vulnerability-disclosures

The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
https://openssf.org
Apache License 2.0
180 stars 40 forks source link

[RFC] Becoming and Operating a CNA as an Open Source Org/Project #138

Closed sethmlarson closed 9 months ago

sethmlarson commented 1 year ago

Motivation and Plan

Recently I've seen more Open Source projects have a desire to have input into the CVE process and to do so today requires becoming a CNA, something which can seem daunting at first glance.

Recently the PSF has been authorized as a CNA. I wanted to create some guidance from what the PSF team learned from going through the revamped process, to add visibility into all steps of the process, and answer common questions that Open Source projects specifically might ask during onboarding.

Once the PSF has gotten more experience as a CNA I plan to create a second piece of guidance ("Operating a CNA as an Open Source Organization or Project") that will serve to really show if the "juice is worth the squeeze".

Links

zmanion commented 1 year ago

Great idea and it should be possible to get relevant feedback integrated back into the CVE Program practices and documents (I offer to help with that if needed).

Also an option for some projects (for whom the juice may not be worth the squeeze) is to request CVE IDs from more "local" CNAs such as Red Hat or GitHub.

sethmlarson commented 1 year ago

@zmanion Agreed! I'll keep a list of items that aren't covered in CNA Rules or documented until after you begin onboarding:

SecurityCRob commented 1 year ago

STRONG endorse of Seth's work putting this together to share with the community.

SecurityCRob commented 9 months ago

This can be closed, correct @sethmlarson ? This is out now I think.

sethmlarson commented 9 months ago

Oh yes this is complete! Thought it was setup to auto-close on the PR :)

cqueern commented 9 months ago

Thanks for your hard work here, team. Is there a link to the final product available?