Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 10 additions & 6 deletions src/pages/security.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,12 +39,16 @@ team](https://www.apache.org/security/) via email to
vulnerability, how it might be exploited, and any additional information that
might be useful.

Upon notification, the ASF security team will work with the CloudStack PMC
through validation and fixing the issue. If the issue is validated, it generally
takes 2-4 weeks from notification to public announcement of the vulnerability.
During this time, the team will communicate with you as they proceed through the
response procedure, and ask that the issue not be announced before an
agreed-upon date.
Upon notification, the ASF security team will work with the CloudStack
PMC through validation and fixing the issue. If the issue is
validated, it will still take time to fix the issue. The amount of
time depends on the availability of volunteers and number people
involved that have a stake in the issue. In later years it has turned
Comment on lines +44 to +46
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It might make sense to mention that the round-trip time also depends on the severity of the issue? Hopefully severe issues won't be open for six months ;)

out to take up to six months, from notification to public announcement
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

do we need to be specific here? I don't think we need to mention this whole sentence at all

of the vulnerability, due to parallel work on multiple issues. During
Comment on lines +47 to +48
Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
out to take up to six months, from notification to public announcement
of the vulnerability, due to parallel work on multiple issues. During
out to take up more and more time from notification to public announcement
of the vulnerability, due to parallel work on multiple issues. During

@borisstoyanov @raboof ?

this time, the team will communicate with you as they proceed through
the response procedure, and ask that the issue not be announced before
an agreed-upon date.

**Please do not create publicly-viewable JIRA tickets related to the issue**. If
validated, a JIRA ticket with the security flag set will be created for tracking
Expand Down
Loading