docs: securityprocess: Instruct security issue submitters to avoid archives

Archives (as witnessed by recent reports) hide useful information by
requiring the maintainer to download the archive which may be dangerous.

Recent submissions also contained a lot of fluff inside the archives.

Instruct submitters of security issues to attach files directly instead
of hiding them in an archive.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
This commit is contained in:
Peter Krempa
2026-08-11 17:13:43 +02:00
parent 27905cbe57
commit 3a107ffe97
+4
View File
@@ -20,6 +20,10 @@ apply to the core project.
Ensure that the "**turn on confidentiality**" checkbox is selected prior to
submitting the issue, to restrict visibility to project maintainers only.
.. important::
Only attach plain files, do not bundle files in archives (zip, tar, etc.)
without prior request from a libvirt maintainer.
Maintainer(s) will analyse the reported disclosure and decide whether it
is to be classed as a security flaw or not. If not a security flaw, the
``confidential`` tag will be removed immediately. If a security flaw,