diff options
| author | Richard Purdie <richard.purdie@linuxfoundation.org> | 2023-10-24 12:58:24 +0100 |
|---|---|---|
| committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2023-10-24 13:10:32 +0100 |
| commit | fcc391ebcd836c81284ad785f88bbd3c6cfd1f8a (patch) | |
| tree | b2f5bb1f5bc29d61554b56cd9daa9167db40c32a | |
| parent | 0ac25662c7555fe0033637ffb0b449d160b5bf4b (diff) | |
| download | poky-fcc391ebcd836c81284ad785f88bbd3c6cfd1f8a.tar.gz | |
SECURITY.md: Add file
Add a SECURITY.md file with hints for security researchers and other
parties who might report potential security vulnerabilities.
(From meta-yocto rev: c8f27eaa00fdd1a2594aaa70695373f608ff30bb)
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
| -rw-r--r-- | SECURITY.md | 24 |
1 files changed, 24 insertions, 0 deletions
diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000000..7d2ce1f631 --- /dev/null +++ b/SECURITY.md | |||
| @@ -0,0 +1,24 @@ | |||
| 1 | How to Report a Potential Vulnerability? | ||
| 2 | ======================================== | ||
| 3 | |||
| 4 | If you would like to report a public issue (for example, one with a released | ||
| 5 | CVE number), please report it using the | ||
| 6 | [https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Security Security Bugzilla]. | ||
| 7 | If you have a patch ready, submit it following the same procedure as any other | ||
| 8 | patch as described in README.md. | ||
| 9 | |||
| 10 | If you are dealing with a not-yet released or urgent issue, please send a | ||
| 11 | message to security AT yoctoproject DOT org, including as many details as | ||
| 12 | possible: the layer or software module affected, the recipe and its version, | ||
| 13 | and any example code, if available. | ||
| 14 | |||
| 15 | Branches maintained with security fixes | ||
| 16 | --------------------------------------- | ||
| 17 | |||
| 18 | See [https://wiki.yoctoproject.org/wiki/Stable_Release_and_LTS Stable release and LTS] | ||
| 19 | for detailed info regarding the policies and maintenance of Stable branches. | ||
| 20 | |||
| 21 | The [https://wiki.yoctoproject.org/wiki/Releases Release page] contains a list of all | ||
| 22 | releases of the Yocto Project. Versions in grey are no longer actively maintained with | ||
| 23 | security patches, but well-tested patches may still be accepted for them for | ||
| 24 | significant issues. | ||
