Skip to content

Define CVE Embargo policy and process #57

@karras

Description

@karras

In order to improve and align our security-related activities, we should define an embargo policy and process for OpenBao-related vulnerabilities.

The Dev WG has put together the following high-level approach in its recent meeting (2025-09-04):

  • Use GitHub Advisories to collaborate on the necessary patches
    • GH Advisories expose a kind of "out of org" fork/branch only shared with those which are involved
  • 90 days for patch development
  • There should be early announcements of upcoming disclosures, similar to other projects
  • Access to patched binaries ahead of time is restricted to the Dev WG (voting members) and TSC
    • Limited to self-running it
    • Feedback on the stability and remediated issues is appreciated

A first draft should be published which can then be vetoed by the TSC/Dev WG, if there are reasonable concerns.

Metadata

Metadata

Assignees

Labels

documentationDocumentation improvements and technical writingwg/supplyTopics related to the Supply Chain Security working group

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions