Security Policy Discussion #575
Replies: 9 comments 11 replies
-
This sounds like a great idea! |
Beta Was this translation helpful? Give feedback.
-
Did you have any thoughts on what should go in there @kinggoesgaming? |
Beta Was this translation helpful? Give feedback.
-
Will brainstorm on this on my commute to work tomorrow |
Beta Was this translation helpful? Give feedback.
-
So after sleeping over the matter, I think these these questions need to be addressed: Who/ How to contact?
Time to contact the reporting party?
Security support lifetime? What to do when we cannot resolve a vulnerability in a version due to MSRV? What What about How to publicly report the vulnerability?
What versions are just to be yanked vs get a update version? Update policy?
@KodrAus if you think you have any other questions/ issues to be raised, add to the list. For the matter of clarity it's best to either do each point as a separate comment; or move this to Discussions. |
Beta Was this translation helpful? Give feedback.
-
I will start adding my 2 cents tonight after work |
Beta Was this translation helpful? Give feedback.
-
|
Beta Was this translation helpful? Give feedback.
-
Who/ How to contact?
|
Beta Was this translation helpful? Give feedback.
-
Some prior art here: https://github.com/tokio-rs/tokio/blob/master/SECURITY.md One difference is that |
Beta Was this translation helpful? Give feedback.
-
What |
Beta Was this translation helpful? Give feedback.
-
Before we do release
1.0,0
, we need to determine how we deal with any vunerablilities that show up in the crate or any deps that we have.Also setup the Security Policy file.
Beta Was this translation helpful? Give feedback.
All reactions