•  
      request #35827 Document vulnerability disclosure process
    Infos
    #35827
    Thomas Gerbet (tgerbet)
    2024-03-14 11:49
    2024-01-05 09:45
    37413
    Details
    Document vulnerability disclosure process

    The disclosure process of Tuleap vulnerabilities is not documented, it should be.

    The goals are:

    • to give clear expectations to security researchers / finders on what they can expect when they report a vulnerability
    • to make it easier for Tuleap integrators to take part of the process if needed (it can only be easier than what it is today as the whole process only really lives in my head...)
    • OSS part for ISO 27001 A.8.8...

    Expected documents at the end of this request:

    • a guide describing and explaining the whole process
    • a runbook summarizing the process to make it easy to follow
    • templates to communicate with security researchers / finders and creating advisories

    The security policy might also be slightly adjusted.

    Other
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2024-03-14
    Attachments
    Empty
    References

    Follow-ups