Skip to content

Commit

Permalink
Merge branch 'sonic-net:master' into aggVoq
Browse files Browse the repository at this point in the history
  • Loading branch information
vivekverma-arista authored May 16, 2024
2 parents f4d03c5 + c256972 commit b8ed520
Show file tree
Hide file tree
Showing 124 changed files with 9,985 additions and 874 deletions.
110 changes: 110 additions & 0 deletions MoM.html
Original file line number Diff line number Diff line change
Expand Up @@ -104,6 +104,116 @@ <h2>SONiC community meeting minutes </h2>
<th style=" text-align: center; ">Links To Meeting Agenda</th>
<th style=" text-align: center; ">Links To Minutes Of The meeting</th>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Apr 30 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/697">No Meeting</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/697">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Apr 23 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/blob/1e3a3d434a0149e450bb034b241d8d93e10b41b7/doc/Dhcp_Mitigation/DHCP%20Mitigation.md">DHCP DoS Mitigation HLD</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/695">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Apr 16 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/blob/4af2854edd9581507e023f942f86627352f89bf4/doc/wcmp/wcmp-design.md">WECMP HLD</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/688">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Apr 09 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/blob/5f9c839ac239a5d3532b18163b348c20f3468a15/doc/decap/subnet_decap_HLD.md">Subnet_Decap HLD</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/684">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Apr 02 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/pull/1644">GNOI HLD</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/677">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Mar 26 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/pull/1631">PoE HLD</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/676">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Mar 19 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/sonic-swss/pull/1752">WCMP HLD</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/665">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Mar 12 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/pull/1621">BGP monitoring HLD</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/660">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Mar 05 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/641">No Meeting</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/641">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Feb 27 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/pull/1481">Storage Mon HLD</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/640">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Feb 20 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/pull/1587">Aggregate VOQ counters HLD</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/622">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Feb 13 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/issues/1520">Fault Management Analysis and Handling</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/612">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Feb 06 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/pull/1572">Add SONiC Debian Upgrade Cadence HLD</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/595">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Jan 30 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/pull/1570">Express Reboot HLD</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/592">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Jan 23 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/pull/1580">SONiC ACL based Metering HLD</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/585">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Jan 16 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/pull/1471">TACACS+ Passkey Encryption</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/577">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Jan 09 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/pull/1577">SONiC long reset button press</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/575">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Jan 02 2024 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/566">No Meeting</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/566">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Dec 26 2023 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/549">No Meeting</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/549">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Dec 19 2023 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/548">No Meeting</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/563">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Dec 12 2023 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/sonic-net/SONiC/pull/1533">Handle ASIC/SDK Health event</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/560">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Dec 05 2023 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://github.com/orgs/sonic-net/projects/17">202405 Release planning</a></td>
<td style=""><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/552">MoM</a></td>
</tr>
<tr>
<td style="">&nbsp;&nbsp;Nov 28 2023 &nbsp;&nbsp;</td>
<td style="text-align: left; "><a href="https://lists.sonicfoundation.dev/g/sonic-dev/message/540">No Meeting</a></td>
Expand Down
19 changes: 19 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# **Security Vulnerability Management Process for SONiC Community**
This document outlines SONiC vulnerability reporting and management process. SONiC is a popular choice of cloud providers, enterprises, telecom providers, web service providers and others to build their digital infrastructure. The security of SONiC is vital for the safety and reliability of our digital transformation. The strong and active cooperation among SONiC community members is key to securing SONiC. This process will be shared through https://github.com/sonic-net/SONiC/SECURITY.md file after TSC approval. The diagram below illustrates the high-level workflow:
![](./images/security-process/security.png)
## 1.Report SONiC Vulnerability
As a SONiC community member, it is your responsibility to report the discovered vulnerabilities before public disclosure. If you want to report a vulnerability, please use the template suggested by SONiC security committee, encrypt your email and privately send it to security@lists.sonicfoundation.dev. Only SONiC security committee members can access the information in this security mailing list, and they also watch over this mailing list. When someone reports a new vulnerability, SONiC security committee will assist with the vulnerability assessment, coordinate on the mitigation and fix. If you have a suggested fix or mitigation, please include it in your report. Exploit instruction is very useful and will be kept confidential unless it is already public (published to the CVE® database or other publicly accessible websites and mail lists). SONiC security committee may seek help from SONiC repo maintainers or other domain experts to look into the vulnerability and prepare a mitigation/fix. The collaboration and communication will be private.
We appreciate security researchers and SONiC users that report vulnerabilities to the SONiC Open Source Community. All reports will be investigated thoroughly by the SONiC security committee.
## 2.Vulnerability Disclosure
Once a mitigation/fix is reviewed and approved by SONiC security committee, the vulnerability disclosure process starts.
Mitigation/fix for public known vulnerabilities will be released right away once approved by SONiC security committee. Fix/mitigation for non-public vulnerabilities should also come out as soon as possible, but we may postpone them if the reporter or an affected party request so. However, the delay should be no more than 90 days from when a mitigation/fix is ready. The SONiC security committee should create a template for disclosing vulnerability.
The vulnerability and fix will be published to sonic-security-announce@lists.sonicfoundation.dev and sonic-dev@lists.sonicfoundation.dev mailing list and a dedicated wiki page hosted in [https://github.com/sonic-net/SONiC](https://github.com/sonic-net/SONiC) repo.
Our focus is on getting vulnerability mitigated as soon as possible. All other information submitted to the security list and any follow-up discussions of the report are treated confidentially even after the embargo has been lifted, in perpetuity.

## 3.SONiC Security Committee
The SONiC security committee is the group that can view the reported vulnerability information, assign investigators for the vulnerability, coordinate the mitigation/fix preparation and approve the final mitigation/fix. The security committee also defines the SONiC security strategy.
Each TSC member can nominate a representative to initiate the security committee. Subsequent requests to join the security committee require review and approval by existing members. If a company loses their TSC membership, its representative should also be removed from the security committee. The security committee has a chairman and nominated by the TSC chair. The chairman will coordinate the vulnerability triage, mitigation preparation and security strategy documentation.
The security committee meets regularly to discuss the current security status of SONiC, review any pending vulnerabilities, and plan for future security improvements. The security committee reports to the TSC on a quarterly basis, the details of undisclosed vulnerability will not be reported.
## 4.CVE Assignment
SONiC security committee does not issue CVEs. Reporters should figure out their own way to issue CVE, but the CVE should not be made public before the SONiC security committee discloses the vulnerability. However, SONiC security committee will not postpone a patch update to wait for a CVE published.

Loading

0 comments on commit b8ed520

Please sign in to comment.