-
Notifications
You must be signed in to change notification settings - Fork 31
docs: add security policy and vulnerability reporting page #553
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
/staging |
Your PR has been deployed to staging. Staging URL: https://static.staging.kernelci.org/ After testing, you can merge your PR. Note: This is a temporary staging URL, if anyone else will test another PR, it will override contents. |
I wonder if pointers to Linux Kernel security resources might also be wise. I can see people getting confused reporting a kernel issue to KernelCI when that would obviously be incorrect. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank you for the PR @padovan!
|
||
If you discover a security vulnerability in any KernelCI project, please report it responsibly by emailing: | ||
|
||
**[[email protected]](mailto:[email protected])** |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is this temporary until a "security" email is set up? Or are we going to stick with using this address?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
personally I would prefer to have something like kernelci-security or security
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't see an issue in using the sysadmin one for the time being. I expect that the use of this email for security report will be very low. Having another mailing list will add overhead to manage that as well, so I'd start small here.
Signed-off-by: Gustavo Padovan <[email protected]>
c83327d
to
6683336
Compare
/staging |
Your PR has been deployed to staging. Staging URL: https://static.staging.kernelci.org/ After testing, you can merge your PR. Note: This is a temporary staging URL, if anyone else will test another PR, it will override contents. |
No description provided.