/wg-vulnerability-disclosures

Our vision is an open source software ecosystem where the time to fix a vulnerability and deploy that fix across the ecosystem is measured in minutes, not months.

Apache License 2.0Apache-2.0

Vulnerability Disclosures

Our vision is an open source software ecosystem where the time to fix a vulnerability and deploy that fix across the ecosystem is measured in minutes, not months.

Objectives and Key Results (CY 2020)

The first objectives we're using to track our progress towards that vision are:

  • Create a unified format and API for vulnerability reporting (from researchers to maintainers) and drive broad adoption of it across the open source software ecosystem
  • Create a unified format, API, and process for coordinated disclosure (from maintainers to users/the world) and drive broad adoption

Outputs

Governance

The CHARTER.md outlines the scope and governance of our group activities.

Meetings

Schedule

The working group meets every three weeks, on Monday at 7am Pacific. Currently we are using Zoom for working group meetings.

Contact Marcin for calendar details.

Agenda

Meeting agenda is published prior to the meeting in a GitHub issue with the label meeting. The issue contains agenda items and logistics details like date, time, Zoom link and a link to meeting notes document.

Who is in this Working Group?

We use the vulnerability-disclosures-wg GitHub team.