]> xenbits.xensource.com Git - people/larsk/security-process.git/log
people/larsk/security-process.git
12 years agoClean up minor inconsistency re public disclosure
George Dunlap [Thu, 15 Nov 2012 15:52:08 +0000 (15:52 +0000)]
Clean up minor inconsistency re public disclosure

Include a summary of both kinds of e-mail which may be sent to the
pre-disclosure list in the "Pre-disclosure list" section, before the
discussion of what is expected of pre-disclosure list members.  Also
make it consistently clear that the public disclosure will always be
sent to the pre-disclosure list.

Signed-off-by: George Dunlap <george.dunlap@eu.citrix.com>
12 years agoDeclare version 1.3
Ian Campbell [Thu, 16 Aug 2012 15:12:05 +0000 (16:12 +0100)]
Declare version 1.3

12 years agoPatch review, expert advice and targetted fixes
Ian Campbell [Thu, 16 Aug 2012 15:05:01 +0000 (16:05 +0100)]
Patch review, expert advice and targetted fixes

See <20448.49637.38489.246434@mariner.uk.xensource.com>, section
    "Patch development and review"

12 years agoDiscuss post-embargo disclosure of potentially controversial private decisions
Ian Campbell [Thu, 16 Aug 2012 14:45:06 +0000 (15:45 +0100)]
Discuss post-embargo disclosure of potentially controversial private decisions

See <20448.49637.38489.246434@mariner.uk.xensource.com>, section
    "11. Transparency"

12 years agoClarify the scope of the process to just the hypervisor project
Ian Campbell [Thu, 16 Aug 2012 14:27:00 +0000 (15:27 +0100)]
Clarify the scope of the process to just the hypervisor project

Other projects are handled on a best effort basis by the project lead
with the assistance of the security team.

See <20448.49637.38489.246434@mariner.uk.xensource.com>, section
    "9. Vulnerability process scope"

12 years agoClarifications to predisclosure list subscription instructions
Ian Campbell [Thu, 16 Aug 2012 14:11:18 +0000 (15:11 +0100)]
Clarifications to predisclosure list subscription instructions

Specially:
  * Mention that subscriptions via the webterface do not work / are
    not honoured.
  * Mention the preference for role addresses only.

See <20448.49637.38489.246434@mariner.uk.xensource.com>, section
    "8. Predisclosure subscription process, and email address
        criteria"

12 years agoClarify what info predisclosure list members may share during an
Ian Campbell [Thu, 16 Aug 2012 14:04:43 +0000 (15:04 +0100)]
Clarify what info predisclosure list members may share during an
embargo

See <20448.49637.38489.246434@mariner.uk.xensource.com>, section
  "7. Public communications during the embargo period"

12 years agoBaseline version.
Ian Campbell [Thu, 16 Aug 2012 14:04:06 +0000 (15:04 +0100)]
Baseline version.

Downloaded from
http://www.xen.org/projects/security_vulnerability_process.html
at Thu Aug 16 15:04:25 BST 2012