Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add a company wide SECURITY.md? #6

Open
sed-i opened this issue Jun 15, 2023 · 1 comment
Open

Add a company wide SECURITY.md? #6

sed-i opened this issue Jun 15, 2023 · 1 comment

Comments

@sed-i
Copy link

sed-i commented Jun 15, 2023

We should probably add a SECURITY.md file to all relevant repos.

Perhaps we could link to a company-wide SECURITY.md (example)?

@eslerm
Copy link
Member

eslerm commented Jul 17, 2024

Yes please \o/

Please see https://warthogs.atlassian.net/browse/SEC-4238

As I understand it, we are waiting for GitHub Private Security Reporting to be officially ACK'd before proceeding (so that projects can decide if they want e-mail or GH reporting in the SECURITY.md).

The proposed text is loosely based on the OpenSSF's suggestions:

To report a security issue, please email security@ubuntu.com with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue.

Our vulnerability management team intends to respond within 3 working days of your report. If the issue is confirmed to be a vulnerability we will assign a CVE. This project aims to resolve all vulnerabilities within 90 days.

The Ubuntu Security disclosure and embargo policy contains more information about what you can expect when you contact us, and what we expect from you.

(Projects may elect to change the email contact, this is just the default suggestion.)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants