-
Notifications
You must be signed in to change notification settings - Fork 7
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Adds security.md. #1379
Adds security.md. #1379
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Going to https://github.com/Canonical/jimm/security/advisories/new returns a 404
I think this is missing detail, this is really just the temlate they given us but lxd is more in depth. https://github.com/canonical/lxd/blob/main/SECURITY.md This is much nicer and also the file name should be capitlised I think... We should say what versions we're willing to fix. I.e., juju last major latest minor, current, and maybe next major?... |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
requesting changes on file name and some details on what we're willing to fix (i.e., versioning)
95fc860
to
e0b5757
Compare
0ba31cd
to
379074f
Compare
The LXD GitHub admins will be notified of the issue and will work with you | ||
to determine whether the issue qualifies as a security issue and, if so, in | ||
which component. We will then handle figuring out a fix, getting a CVE | ||
assigned and coordinating the release of the fix to the various Linux | ||
distributions. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This needs fixing to be about JAAS not LXD and the bit at the end about "various Linux distributions" doesn't apply.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
bar kians comment
Description
Adds security.md as part of the vulnerability and response.
Engineering checklist
Check only items that apply
Test instructions
Notes for code reviewers