zephyriot / zep-jira14

0 stars 0 forks source link

Ability to make Security / Vulnerability bugs non-public #1174

Open nashif opened 7 years ago

nashif commented 7 years ago

Reported by Mark Linkmeyer:

See Summary

(Imported from Jira ZEP-1296)

nashif commented 7 years ago

by Inaky Perez-Gonzalez:

Mark Linkmeyer who do I have to contact in the JIRA admins to make this possible?

nashif commented 7 years ago

by Mark Linkmeyer:

Hi Inaky Perez-Gonzalez , you'll need to make a proposal to the Zephyr Process WG on how you'd like to change Jira to support this. Once the changes are approved we'll get Andy of The Linux Foundation to make the change. The Zephyr Process WG meets every Monday at 9am PST. Let me know when you want on the agenda. There's time in next Monday's meeting, if you're ready.

nashif commented 7 years ago

by Inaky Perez-Gonzalez:

Proposal:

nashif commented 7 years ago

by Inaky Perez-Gonzalez:

Anas, I probably won't be able to attend the 7am SWG this Friday -- in case I don't, can you bring the proposal forward on my behalf? I was supposed to present it.

nashif commented 7 years ago

by Anas Nashif:

assigning back to you, we did not get to it last meeting, so you can address this in the next meeting.

nashif commented 7 years ago

by Inaky Perez-Gonzalez:

ARs: do more research on CVE assignment and interaction, vetting process for new security issues (accepted as embargoed or not), adding an embargo end date field.

nashif commented 7 years ago

by Andy Gross:

Need to add one thing to the accessibility control section: Ability to add other users for individual issues

nashif commented 7 years ago

by Mark Linkmeyer:

Hi Andy Gross , what needs to happen on this yet to get the proposal approved? I ask because I'd like to drive getting Jira updated accordingly, once it's approved. I see your comment from May 5th, but it's not clear who needs to (or who will) add what you mention as needed. To whom was your comment directed?

nashif commented 7 years ago

by Andy Gross:

Mark,

This was to Inaky. Is there someone else who should be driving this from an implementation standpoint?

nashif commented 7 years ago

by David Brown:

A couple of thoughts on the implementation: