Formalise Vulnerability Response Process
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Stale
- Domain
- documentation, security
Research direction
Start by reading the referenced OSSF OSS Vulnerability Guide and inspecting this repository for any existing security-process material. Define the end-to-end handling and response steps described by the issue, then document the agreed process in the repository. Done means the vulnerability-report workflow is formally documented from receipt through resolution.
Written by the indexing model from the issue text.
Description
There's no documentation on the how we handle and respond to vulnerability reports.
This issue is to track creating formal documentation that clearly states end-to-end how a vulnerability report is to be handled.
References
OSSF's OSS Vulnerability Guide: https://github.com/ossf/oss-vulnerability-guide/blob/main/guide.md
- Dominant language
- TypeScript
- Stars
- 4
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from loopbackio/security
-
Difficulty 4/5 3-5 days Newbie friendliness 45/100
loopbackio/security#42 ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
loopbackio/security#41 ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
loopbackio/security#40 ·
-
openjsf
Difficulty 5/5 Over a week Newbie friendliness 25/100
loopbackio/security#39 ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
loopbackio/security#38 ·
All issues in loopbackio/security
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Eynzof/Hermes-CN-Desktop#610 ·
-
bug clawsweeper:linked-pr-open clawsweeper:needs-live-repro clawsweeper:no-new-fix-pr impact:message-loss issue-rating: 🐚 platinum hermit P2 regression
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
calcite-components needs triage refactor
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Esri/calcite-design-system#15203 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 78/100
fullcalendar/fullcalendar#8106 ·