Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add security disclosure principles #1650

Merged
merged 1 commit into from
Jan 29, 2021
Merged

Add security disclosure principles #1650

merged 1 commit into from
Jan 29, 2021

Conversation

teor2345
Copy link
Contributor

Motivation

Our security disclosure policy talks about what we do with disclosures, but its purpose, goals, and principles aren't clear.

Solution

Make our security disclosure goals and principles explicit, including:

  • prioritising users and researchers
  • assuming good faith
  • operating a no fault process
  • working with researchers regardless of how they disclose
    (but we prefer this process)

Review

@dconnolly wrote the policy, the review isn't urgent.

Related Issues

Closes #1641

Follow Up Work

#1638 Create PGP keys for security@...

@teor2345 teor2345 added A-docs Area: Documentation P-Medium labels Jan 28, 2021
@teor2345 teor2345 added this to the 2021 Sprint 2 milestone Jan 28, 2021
@teor2345 teor2345 requested a review from dconnolly January 28, 2021 08:07
@teor2345 teor2345 self-assigned this Jan 28, 2021
Make our security disclosure goals and principles explicit, including:
- prioritising users and researchers
- assuming good faith
- operating a no fault process
- working with researchers regardless of how they disclose
  (but we prefer this process)
@dconnolly dconnolly force-pushed the security-principles branch from 6070fa7 to f52609c Compare January 29, 2021 22:39
@dconnolly dconnolly enabled auto-merge (rebase) January 29, 2021 22:40
@dconnolly dconnolly merged commit 7ad0903 into main Jan 29, 2021
@dconnolly dconnolly deleted the security-principles branch January 29, 2021 22:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
A-docs Area: Documentation
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Security policy addendum
2 participants