From: Ian Jackson
Date: Fri, 16 Jan 2015 19:50:35 +0000 (+0000)
Subject: Add headings
X-Git-Url: http://xenbits.xensource.com/gitweb?a=commitdiff_plain;h=13433fa5af19d4c5a304acb34f2601bdd95ab00b;p=people%2Flarsk%2Fsecurity-process.git
Add headings
- For Predisclosure list application process
- For Handling of embargoed information"
No semantic change.
Signed-off-by: Ian Jackson
Signed-off-by: Ian Jackson
---
diff --git a/security_vulnerability_process.html b/security_vulnerability_process.html
index 4ed0042..010cf76 100644
--- a/security_vulnerability_process.html
+++ b/security_vulnerability_process.html
@@ -186,6 +186,7 @@ addresses.)
of the advisory and patches, with a clearly marked embargo date, as
soon as they are available. The pre-disclosure list will also receive
copies of public advisories when they are first issued or updated
+Handling of embargoed information
Organizations on the pre-disclosure list are expected to maintain
the confidentiality of the vulnerability up to the embargo date which
security@xenproject have agreed with the discoverer, and are
@@ -214,6 +215,7 @@ following:
NOTE: Prior v2.2 of this policy (25 June 2014) it was
permitted to also make available the allocated CVE number. This is no
longer permitted in accordance with MITRE policy.
+Predisclosure list membership application process
Organisations who meet the criteria should contact
security@xenproject if they wish to receive pre-disclosure of
advisories. Please include in the e-mail: