mirror of
https://github.com/ceph/ceph
synced 2025-04-28 13:49:12 +00:00
doc/security: enrich seventh listitem
This PR improves the language of the seventh listitem in the Vulnerability Management Process in the security documentation. Signed-off-by: Zac Dover <zac.dover@gmail.com>
This commit is contained in:
parent
f6b24ece91
commit
b4058169ed
@ -15,13 +15,13 @@ Vulnerability Management Process
|
||||
and share the mutually agreed disclosure date with the reporter.
|
||||
#. The vulnerability disclosure / release date is set excluding Friday and
|
||||
holiday periods.
|
||||
#. Embargoes are preferred for Critical and High impact
|
||||
issues. Embargo should not be held for more than 90 days from the
|
||||
date of vulnerability confirmation, except under unusual
|
||||
circumstances. For Low and Moderate issues with limited impact and
|
||||
an easy workaround or where an issue that is already public, a
|
||||
standard patch release process will be followed to fix the
|
||||
vulnerability once CVE is assigned.
|
||||
#. Embargoes are preferred for "Critical" and "High impact" issues. Embargoes
|
||||
should not be in effect for more than 90 days from the date of the
|
||||
confirmation of the vulnerability, except under unusual circumstances. For
|
||||
"Low" and "Moderate" issues with limited impact and an easy workaround (or
|
||||
in cases where an issue is already public), a unique CVE identifier will be
|
||||
assigned and then a standard patch release process will be followed to fix
|
||||
the vulnerability.
|
||||
#. Medium and Low severity issues will be released as part of the next
|
||||
standard release cycle, with at least a 7 days advanced
|
||||
notification to the list members prior to the release date. The CVE
|
||||
|
Loading…
Reference in New Issue
Block a user