Skip to content

[SEG-WG] Set up process for premature disclosure #6

@avivkeller

Description

@avivkeller

As with every software, eventually, someone may report a security issue as a public issue. In the event of a premature disclosure, we should have a contingency plan set up.

At @nodejs, this goes something along the lines of:

  1. Transfer the issue to a private repository
  2. Prepare and discuss a patch in the private repository
  3. Issue a security release via a push directly to the public repository

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions