History log of /openbmc/docs/security/obmc-security-response-team-guidelines.md (Results 1 – 9 of 9)
Revision Date Author Comments
# 67032dff 02-Dec-2024 Peter Delevoryas <peter@pjd.dev>

ci: Apply prettier lint suggestions

This is blocking [new proposals][1] from passing CI.

[1]: https://gerrit.openbmc.org/c/openbmc/docs/+/76147

Change-Id: I3df57bd4e1abec93cb1775aa291295de9fa083f2

ci: Apply prettier lint suggestions

This is blocking [new proposals][1] from passing CI.

[1]: https://gerrit.openbmc.org/c/openbmc/docs/+/76147

Change-Id: I3df57bd4e1abec93cb1775aa291295de9fa083f2
Signed-off-by: Peter Delevoryas <peter@pjd.dev>

show more ...


# 85706020 04-Jun-2024 Andrew Geissler <geissonator@yahoo.com>

update formatting for new markdown rules

Something got updated in the docker container that has some new rules on
document formatting.

Change-Id: I5b8d3cdc04458845a22d1e898dfbbd7538f68f69
Signed-of

update formatting for new markdown rules

Something got updated in the docker container that has some new rules on
document formatting.

Change-Id: I5b8d3cdc04458845a22d1e898dfbbd7538f68f69
Signed-off-by: Andrew Geissler <geissonator@yahoo.com>

show more ...


# f4febd00 08-Dec-2022 Patrick Williams <patrick@stwcx.xyz>

prettier: re-format

Prettier is enabled in openbmc-build-scripts on Markdown, JSON, and YAML
files to have consistent formatting for these file types. Re-run the
formatter on the whole repository.

prettier: re-format

Prettier is enabled in openbmc-build-scripts on Markdown, JSON, and YAML
files to have consistent formatting for these file types. Re-run the
formatter on the whole repository.

Change-Id: I35ec9c19ae581e4dd00b515c1bba3a9c1862eeb1
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>

show more ...


# 16e8d573 22-Sep-2022 Joseph Reynolds <joseph-reynolds@charter.net>

Add maintainer flow to create security advisories

This enhances the security response guidelines with process steps for
repo maintainers to create new security advisories, and provides
guidance for

Add maintainer flow to create security advisories

This enhances the security response guidelines with process steps for
repo maintainers to create new security advisories, and provides
guidance for what to put into the advisory.

Signed-off-by: Joseph Reynolds <joseph-reynolds@charter.net>
Change-Id: Icc3f737d0d845d651eaf70853ed55529dacf7a93

show more ...


# 106b09c1 27-Jul-2022 Joseph Reynolds <joseph-reynolds@charter.net>

Use github security advisories

This updates the OpenBMC security vulnerability reporting process
to use GitHub advisories. Each repository owner/maintainer is
responsible for their security problem

Use github security advisories

This updates the OpenBMC security vulnerability reporting process
to use GitHub advisories. Each repository owner/maintainer is
responsible for their security problems, and the security response
team advises and creates CVEs.

Signed-off-by: Joseph Reynolds <joseph-reynolds@charter.net>
Change-Id: Ic9e169b4c94b625c9af838ef0c03c78fa0300031

show more ...


# 5fa97051 02-Sep-2021 Joseph Reynolds <joseph-reynolds@charter.net>

Security response team membership guidelines

This better articulates the guidelines for who should be on the
security response team and clarifies that membership is based on
participating organizati

Security response team membership guidelines

This better articulates the guidelines for who should be on the
security response team and clarifies that membership is based on
participating organizations.

Signed-off-by: Joseph Reynolds <joseph-reynolds@charter.net>
Change-Id: Ia331bf1dec4e75b86d448561c82f4096c9a17c12

show more ...


# 20433f04 10-Jan-2019 Joseph Reynolds <jrey@us.ibm.com>

Improve security response docs

This improves the security response team docs

This helps set submitter expectations and controls behavior.

This clarifies that the decision to spread information abo

Improve security response docs

This improves the security response team docs

This helps set submitter expectations and controls behavior.

This clarifies that the decision to spread information about reported
security vulnerabilities should be coordinated by security response
team members, and sets critera for that decision.

This corrects spelling errors.

This calls for an email notification when a new security
advisory is created.

Change-Id: I48edb4e819beadf41da2011f63eb9a2ec3dd4ec9
Signed-off-by: Joseph Reynolds <joseph.reynolds1@ibm.com>

show more ...


# 876953d3 11-Feb-2019 Gunnar Mills <gmills@us.ibm.com>

security-response-team: Capitalize Gerrit

Change-Id: I30cb36b2d61f0e57cffeaebaca48623e9b1ba56d
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>


# 01e72e8a 26-Jul-2018 Joseph Reynolds <jrey@us.ibm.com>

Add how to handle private security vulnerabilities

Adds two new documents:
- "How to report a security vulnerability" says how to privately
report a security vulnerability with the intention of g

Add how to handle private security vulnerabilities

Adds two new documents:
- "How to report a security vulnerability" says how to privately
report a security vulnerability with the intention of getting
a fix before public disclosure.
- "Security response team guidelines" is for the security response
team and community members who are responding to privately
disclosed problems and working to provide a fix.

Change-Id: I83475bd4bfa014106ab5c3b50ad81e3488d06ba3
Signed-off-by: Joseph Reynolds <jrey@us.ibm.com>

show more ...