ossf / wg-vulnerability-disclosures

The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
https://openssf.org
Apache License 2.0
175 stars 40 forks source link

RFC: Becoming a CNA as an Open Source organization or project #139

Closed sethmlarson closed 8 months ago

sethmlarson commented 9 months ago

Authored from this draft: https://docs.google.com/document/d/1jo5van4ryPDOd0O7njzqyCBDq0NG-Z-sK2v-l9z7R2s

Please hold off on merging this until it can be discussed by the Vuln Disclosures WG and the CVE Outreach and Community WG (meets next Wednesday, Sept 27th).

cc-ing the reviewers on the Google doc draft: @SecurityCRob @kurtseifried @andrewpollock @zmanion @Cyber-JiuJiteria