-
Notifications
You must be signed in to change notification settings - Fork 353
SECURITY.md update to follow CRA template #2846
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -11,17 +11,38 @@ mailing list, or IRC. Please do **not** create a public issue. | |
|
|
||
| 1. Go to [our security advisory page](https://github.com/containers/ramalama/security/advisories/new) to privately report the vulnerability. | ||
| 2. Provide detailed information about the vulnerability, including: | ||
| - Description of the issue | ||
| - Steps to reproduce | ||
| - Potential impact | ||
| - Suggested fix (if available) | ||
| - **Title**: A concise, descriptive summary of the issue. | ||
| - **Reporter Details**: Your name/handle and affiliation. | ||
|
coderabbitai[bot] marked this conversation as resolved.
|
||
| - **Technical Description**: Detailed information regarding the vulnerability. | ||
| - **Affected Versions**: The specific version(s) or range(s) of software tested. | ||
| - **Reproduction Steps**: A minimal, functional example to reproduce the issue. | ||
| - **Impact Assessment**: Potential exploit scenarios and perceived severity. (optional) | ||
| - **Suggested Fix**: Any proposed patches or mitigations (optional). | ||
| - **Disclosure Status**: Whether this has been shared with other parties or published and your plan for future sharing (e.g., at a conference). | ||
|
|
||
| Your report will be reviewed by the maintainers, and we will work with you to understand and address the issue promptly. | ||
|
|
||
| ### Response Timeline | ||
|
|
||
| We aim to provide an initial acknowledgement of your report within 48 hours. | ||
|
|
||
| Our goal is to assess the report, coordinate fix and disclosure as quickly as possible. All confirmed security vulnerabilities and incidents will be addressed according to severity level and impact on the project. | ||
|
|
||
| ### Contact Information | ||
|
|
||
| Direct all security questions and vulnerability reports to the [security advisory page](https://github.com/containers/ramalama/security/advisories/new) | ||
|
coderabbitai[bot] marked this conversation as resolved.
|
||
|
|
||
| ### What to Expect | ||
|
|
||
| - **Acknowledgment**: We will acknowledge receipt of your vulnerability report within 48 hours | ||
| - **Updates**: We will keep you informed about our progress in addressing the vulnerability | ||
| - **Credit**: We will credit you for the discovery when we publish the fix (unless you prefer to remain anonymous) | ||
|
coderabbitai[bot] marked this conversation as resolved.
|
||
|
|
||
| Thank you for helping keep RamaLama and its users secure! | ||
|
|
||
| ## EU Cyber Resilience Act — Open Source Steward Statement | ||
|
|
||
| This project is stewarded by **Red Hat, Inc.**, an open source software steward as defined in Article 3(14) of the [EU Cyber Resilience Act (Regulation 2024/2847)](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng). | ||
| Contact: [cra-steward@redhat.com](mailto:cra-steward@redhat.com) | ||
|
|
||
| Refer to [Red Hat's security practices and vulnerability management policy](https://access.redhat.com/security/) for detailed information. | ||
|
Comment on lines
+43
to
+48
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win Use the CRA’s hyphenated legal term. Change “open source software steward” to “open-source software steward” on Line [49] to match the terminology defined in Article 3(14). (eur-lex.europa.eu) 🧰 Tools🪛 LanguageTool[grammar] ~49-~49: Use a hyphen to join words. (QB_NEW_EN_HYPHEN) 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
Uh oh!
There was an error while loading. Please reload this page.