-
Notifications
You must be signed in to change notification settings - Fork 134
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security Disclosure Policy #296
Comments
Ping @nodejs/tsc ... thoughts on this? (I accidentally closed this) |
@jasnell Can the title be renamed, as we already have a security disclosure policy? |
to the concern raised by community members, AFAIK members of security are not supposed to disclose information under embargo to their employers, that is at least the rules I've been following. I'd be very interested in how other projects handle ethical disclosure, and potentially early disclosure to companies. |
I think we just need a PR for the text of the policy. |
The text in this PR probably addressed the original issue: nodejs/security-wg#56 |
Believe this docs the expectations https://github.com/nodejs/security-wg/blob/master/processes/security_team_members.md. @jasnell can this issue be closed ? |
No, I'd prefer to keep this open until nodejs/security-wg#58 is resolved. |
This is being picked up by security-wg. Closing. |
@nodejs/tsc @nodejs/ctc ...
One need we have had for quite some time is a formal early disclosure policy for core and ecosystem vulnerabilities. Currently, our process is rather undefined, including the process for who gets admitted to the @nodejs/security group. What is especially undefined are any of the policies around how and to whom we issue early disclosures for security related issues.
One concern that has been brought to my attention by several members of the community is that under our current processes, some commercial organizations have privileged access to security vulnerability information based solely on the fact that their employees are part of the @nodejs/security team, but other organizations who have employees who actively contribute to core do not have an equal opportunity. We've never really been clear on what the expectations are for members of the @nodejs/security team to keep security details embargoed. This ends up creating a bit of an unfair advantage for certain organizations.
It's past time that we need a documented and enforceable ethical disclosure policy. I would argue that we also should have a reasonable early disclosure process that commercial entities may apply for. Obviously there are details to work out here, but I wanted to get the conversation started.
The text was updated successfully, but these errors were encountered: