-
Notifications
You must be signed in to change notification settings - Fork 233
Update outdated SECURITY.md #1677
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
Signed-off-by: alexey semenyuk <[email protected]>
@EnriqueL8 minor update |
@alex-semenyuk this is good but let's use this file https://github.com/LF-Decentralized-Trust/governance/blob/f0c1a4a6dfbef360ec92627d7e5003480b199195/tac/governing-documents/SAMPLE-SECURITY.md please |
Signed-off-by: alexey semenyuk <[email protected]>
SECURITY.md
Outdated
The current Hyperledger Firefly security team is: | ||
|
||
| Name | Email ID | Discord ID | Area/Specialty | | ||
| ---------------- | ------------------ | ---------- | --------------- | |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@EnriqueL8 Could you please help with filling this
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
ah yeah okay, will raise at the community call to see who wants to be part of it. You can at least put my name down
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Follow up on this
Signed-off-by: alexey semenyuk <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We discussed it in the community call that we should specify that if raised through GitHub it should be raised in the specific repository of the component where the vulnerability was found
Correct spelling to Hyperledger FireFly
|
||
## (GitHub) Security Advisories | ||
|
||
Hyperledger Firefly uses GitHub Security Advisories to manage the public |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hyperledger Firefly uses GitHub Security Advisories to manage the public | |
Hyperledger FireFly uses GitHub Security Advisories to manage the public |
- Email the [LF Decentralized Trust Foundation security | ||
list](mailto:[email protected]): To report a security issue, please | ||
send an email with the name of the project/repository, a description of the issue, the | ||
steps you took to create the issue, affected versions, and if known, | ||
mitigations. If in triaging the email, the security team determines the issue may be | ||
a security vulnerability, a [GitHub security vulnerability report] will be | ||
opened. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
FYI @ryjones is this is still the correct process?
Proposed changes
Update outdated SECURITY.md to sync with other LF repos, since some of links outdated. Also it helps to fix Security-Policy issue slightly improving score openssf scorecard
Types of changes
Please make sure to follow these points
Screenshots (If Applicable)
Other Information