The disclosure process of Tuleap vulnerabilities is not documented, it should be.
The goals are:
- to give clear expectations to security researchers / finders on what they can expect when they report a vulnerability
- to make it easier for Tuleap integrators to take part of the process if needed (it can only be easier than what it is today as the whole process only really lives in my head...)
- OSS part for ISO 27001 A.8.8...
Expected documents at the end of this request:
- a guide describing and explaining the whole process
- a runbook summarizing the process to make it easy to follow
- templates to communicate with security researchers / finders and creating advisories
The security policy might also be slightly adjusted.