]> git.ipfire.org Git - thirdparty/libvirt.git/commitdiff
docs: securityprocess: Instruct security issue submitters to avoid archives master
authorPeter Krempa <pkrempa@redhat.com>
Mon, 10 Aug 2026 13:14:40 +0000 (15:14 +0200)
committerPeter Krempa <pkrempa@redhat.com>
Tue, 11 Aug 2026 15:13:43 +0000 (17:13 +0200)
Archives (as witnessed by recent reports) hide useful information by
requiring the maintainer to download the archive which may be dangerous.

Recent submissions also contained a lot of fluff inside the archives.

Instruct submitters of security issues to attach files directly instead
of hiding them in an archive.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
docs/securityprocess.rst

index b9fa8d9890823968920247ad1f9b6e08b8a6ea2b..391d6f7ce6c59a5f2c147a69c9a501f4bcced081 100644 (file)
@@ -20,6 +20,10 @@ apply to the core project.
 Ensure that the "**turn on confidentiality**" checkbox is selected prior to
 submitting the issue, to restrict visibility to project maintainers only.
 
+.. important::
+   Only attach plain files, do not bundle files in archives (zip, tar, etc.)
+   without prior request from a libvirt maintainer.
+
 Maintainer(s) will analyse the reported disclosure and decide whether it
 is to be classed as a security flaw or not. If not a security flaw, the
 ``confidential`` tag will be removed immediately. If a security flaw,