]> git.ipfire.org Git - thirdparty/gnutls.git/commitdiff
Added SECURITY.md, a description of the security issue handling process
authorNikos Mavrogiannopoulos <nmav@redhat.com>
Tue, 21 Feb 2017 07:13:56 +0000 (08:13 +0100)
committerNikos Mavrogiannopoulos <nmav@redhat.com>
Tue, 21 Feb 2017 07:17:10 +0000 (08:17 +0100)
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
SECURITY.md [new file with mode: 0644]

diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644 (file)
index 0000000..34303f1
--- /dev/null
@@ -0,0 +1,32 @@
+# GnuTLS -- Information about our security issue handling process
+
+ Security issues are reported either to [issue tracker](https://gitlab.com/gnutls/gnutls/issues)
+as private bugs, or on the bug report mail address.
+
+The following steps describe the steps we recommend to use to address the
+issue.
+
+# Which issues are security issues
+
+A metric we consult to assessing security vulnerabilities is
+the [CVSS](https://www.first.org/cvss) metric. Only vulnerabilities
+at the high or critical level are handled with this process. Other
+issues are handled with the normal release process.
+
+# Committing a fix
+
+The fix when is made available, preferrably within 3 months of the report,
+is pushed to the repository using a detailed message on all supported
+branches which are affected. The commit message must refer to the bug
+report addressed (e.g., our issue tracker or some external issue tracker).
+
+# Releasing
+
+Currently our releases are time-based, thus there are no special releases
+targetting security fixes. At release time the NEWS entries must reflect
+the issues addressed (also referring to the relevant issue trackers), and
+security-related entries get assigned a GNUTLS-SA (gnutls security advisory
+number). The assignment is done at release time at the web repository, in
+the 'security-entries' path. The number assigned is the year separated
+with a dash with the first unassigned number for the year.
+