mirror of
https://github.com/libvirt/libvirt.git
synced 2026-08-19 01:24:42 -05:00
docs: securityprocess: Instruct security issue submitters to avoid archives
Archives (as witnessed by recent reports) hide useful information by requiring the maintainer to download the archive which may be dangerous. Recent submissions also contained a lot of fluff inside the archives. Instruct submitters of security issues to attach files directly instead of hiding them in an archive. Signed-off-by: Peter Krempa <pkrempa@redhat.com> Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
This commit is contained in:
@@ -20,6 +20,10 @@ apply to the core project.
|
||||
Ensure that the "**turn on confidentiality**" checkbox is selected prior to
|
||||
submitting the issue, to restrict visibility to project maintainers only.
|
||||
|
||||
.. important::
|
||||
Only attach plain files, do not bundle files in archives (zip, tar, etc.)
|
||||
without prior request from a libvirt maintainer.
|
||||
|
||||
Maintainer(s) will analyse the reported disclosure and decide whether it
|
||||
is to be classed as a security flaw or not. If not a security flaw, the
|
||||
``confidential`` tag will be removed immediately. If a security flaw,
|
||||
|
||||
Reference in New Issue
Block a user