]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/blob - SECURITY.md
python-*: don't set PYPI_ARCHIVE_NAME and S when PYPI_PACKAGE is sufficient
[thirdparty/openembedded/openembedded-core.git] / SECURITY.md
1 How to Report a Potential Vulnerability?
2 ========================================
3
4 If you would like to report a public issue (for example, one with a released
5 CVE number), please report it using the
6 [https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Security Security Bugzilla]
7
8 If you are dealing with a not-yet released or urgent issue, please send a
9 message to security AT yoctoproject DOT org, including as many details as
10 possible: the layer or software module affected, the recipe and its version,
11 and any example code, if available.
12
13 Branches maintained with security fixes
14 ---------------------------------------
15
16 See [https://wiki.yoctoproject.org/wiki/Stable_Release_and_LTS Stable release and LTS]
17 for detailed info regarding the policies and maintenance of Stable branches.
18
19 The [https://wiki.yoctoproject.org/wiki/Releases Release page] contains a list of all
20 releases of the Yocto Project. Versions in grey are no longer actively maintained with
21 security patches, but well-tested patches may still be accepted for them for
22 significant issues.