-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Labels
documentationDocumentation improvements and technical writingDocumentation improvements and technical writingwg/supplyTopics related to the Supply Chain Security working groupTopics related to the Supply Chain Security working group
Description
In order to improve and align our security-related activities, we should define an embargo policy and process for OpenBao-related vulnerabilities.
The Dev WG has put together the following high-level approach in its recent meeting (2025-09-04):
- Use GitHub Advisories to collaborate on the necessary patches
- GH Advisories expose a kind of "out of org" fork/branch only shared with those which are involved
- 90 days for patch development
- There should be early announcements of upcoming disclosures, similar to other projects
- Access to patched binaries ahead of time is restricted to the Dev WG (voting members) and TSC
- Limited to self-running it
- Feedback on the stability and remediated issues is appreciated
A first draft should be published which can then be vetoed by the TSC/Dev WG, if there are reasonable concerns.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
documentationDocumentation improvements and technical writingDocumentation improvements and technical writingwg/supplyTopics related to the Supply Chain Security working groupTopics related to the Supply Chain Security working group