Skip to content

Conversation

alex-semenyuk
Copy link
Member

@alex-semenyuk alex-semenyuk commented Apr 17, 2025

Proposed changes

Update outdated SECURITY.md to sync with other LF repos, since some of links outdated. Also it helps to fix Security-Policy issue slightly improving score openssf scorecard


Types of changes

  • Bug fix
  • New feature added
  • Documentation Update

Please make sure to follow these points

  • I have read the contributing guidelines.
  • I have performed a self-review of my own code or work.

Screenshots (If Applicable)


Other Information

Signed-off-by: alexey semenyuk <[email protected]>
@alex-semenyuk
Copy link
Member Author

@EnriqueL8 minor update

@EnriqueL8
Copy link
Contributor

@alex-semenyuk this is good but let's use this file https://github.com/LF-Decentralized-Trust/governance/blob/f0c1a4a6dfbef360ec92627d7e5003480b199195/tac/governing-documents/SAMPLE-SECURITY.md please

Signed-off-by: alexey semenyuk <[email protected]>
SECURITY.md Outdated
The current Hyperledger Firefly security team is:

| Name | Email ID | Discord ID | Area/Specialty |
| ---------------- | ------------------ | ---------- | --------------- |
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@EnriqueL8 Could you please help with filling this

Copy link
Contributor

@EnriqueL8 EnriqueL8 Jul 3, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ah yeah okay, will raise at the community call to see who wants to be part of it. You can at least put my name down

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow up on this

Signed-off-by: alexey semenyuk <[email protected]>
Copy link
Contributor

@EnriqueL8 EnriqueL8 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We discussed it in the community call that we should specify that if raised through GitHub it should be raised in the specific repository of the component where the vulnerability was found

Correct spelling to Hyperledger FireFly


## (GitHub) Security Advisories

Hyperledger Firefly uses GitHub Security Advisories to manage the public
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Hyperledger Firefly uses GitHub Security Advisories to manage the public
Hyperledger FireFly uses GitHub Security Advisories to manage the public

Comment on lines +120 to +126
- Email the [LF Decentralized Trust Foundation security
list](mailto:[email protected]): To report a security issue, please
send an email with the name of the project/repository, a description of the issue, the
steps you took to create the issue, affected versions, and if known,
mitigations. If in triaging the email, the security team determines the issue may be
a security vulnerability, a [GitHub security vulnerability report] will be
opened.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

FYI @ryjones is this is still the correct process?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants