diff options
author | Marta Rybczynska <rybczynska@gmail.com> | 2023-10-24 13:38:38 +0200 |
---|---|---|
committer | Steve Sakoman <steve@sakoman.com> | 2023-10-24 05:22:46 -1000 |
commit | 0d5e5385191b386abce6292e9688018a11c74c63 (patch) | |
tree | b81e52bf9bcaef32512cc953cdd07d11fa319f26 /bitbake | |
parent | 374e198436be1df8bbf1e5bc2487c3cde22c265a (diff) | |
download | poky-0d5e5385191b386abce6292e9688018a11c74c63.tar.gz |
bitbake: SECURITY.md: add file
Add a SECURITY.md file with hints for security researchers and other
parties who might report potential security vulnerabilities.
(Bitbake rev: dd826595414c5dc1a649f45a9dd2430bf6d4699b)
Signed-off-by: Marta Rybczynska <marta.rybczynska@syslinbit.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'bitbake')
-rw-r--r-- | bitbake/SECURITY.md | 24 |
1 files changed, 24 insertions, 0 deletions
diff --git a/bitbake/SECURITY.md b/bitbake/SECURITY.md new file mode 100644 index 0000000000..7d2ce1f631 --- /dev/null +++ b/bitbake/SECURITY.md | |||
@@ -0,0 +1,24 @@ | |||
1 | How to Report a Potential Vulnerability? | ||
2 | ======================================== | ||
3 | |||
4 | If you would like to report a public issue (for example, one with a released | ||
5 | CVE number), please report it using the | ||
6 | [https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Security Security Bugzilla]. | ||
7 | If you have a patch ready, submit it following the same procedure as any other | ||
8 | patch as described in README.md. | ||
9 | |||
10 | If you are dealing with a not-yet released or urgent issue, please send a | ||
11 | message to security AT yoctoproject DOT org, including as many details as | ||
12 | possible: the layer or software module affected, the recipe and its version, | ||
13 | and any example code, if available. | ||
14 | |||
15 | Branches maintained with security fixes | ||
16 | --------------------------------------- | ||
17 | |||
18 | See [https://wiki.yoctoproject.org/wiki/Stable_Release_and_LTS Stable release and LTS] | ||
19 | for detailed info regarding the policies and maintenance of Stable branches. | ||
20 | |||
21 | The [https://wiki.yoctoproject.org/wiki/Releases Release page] contains a list of all | ||
22 | releases of the Yocto Project. Versions in grey are no longer actively maintained with | ||
23 | security patches, but well-tested patches may still be accepted for them for | ||
24 | significant issues. | ||