]> xenbits.xensource.com Git - people/larsk/security-process.git/commit
Tighten, and make more objective, predisclosure list application
authorIan Jackson <ijackson@chiark.greenend.org.uk>
Fri, 16 Jan 2015 19:51:03 +0000 (19:51 +0000)
committerIan Jackson <Ian.Jackson@eu.citrix.com>
Mon, 19 Jan 2015 17:53:37 +0000 (17:53 +0000)
commit82ff8908ebed186b314b0159db4b2faad615f47b
treef2d497a273b878855c68ca4768db6933a11843ce
parent27cacfedd0171ec0d1c163eeb24000466204e62a
Tighten, and make more objective, predisclosure list application

Applicants should be required to:

  - Provide information on their public web pages which makes
    it clear that and why they are eligible;

  - Specifically, publicly state that and how they are using Xen
    (so that the Security Team can verify eligibility);

  - Provide a way for members of the public to responsibly report
    security problems to the applicant, just as the Xen Project does.

The Security Team should be forbidden from trying to hunt down
eligibility information etc. and should instead be mandated to reject
incomplete requests.

Also remove the "case-by-case-basis" membership exception.  This is
not consistent with the new objective membership application process.

Signed-off-by: Ian Jackson <ijackson@chiark.greenend.org.uk>
Signed-off-by: Ian Jackson <Ian.Jackson@eu.citrix.com>
security_vulnerability_process.html