Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update security reporting policy #3595

Closed
tigrannajaryan opened this issue Jul 13, 2023 · 3 comments
Closed

Update security reporting policy #3595

tigrannajaryan opened this issue Jul 13, 2023 · 3 comments
Assignees
Labels
spec:miscellaneous For issues that don't match any other spec label

Comments

@tigrannajaryan
Copy link
Member

tigrannajaryan commented Jul 13, 2023

TC and GC discussed and decided that we want to make Github security reporting capabilities the primary reporting channel.

We will need to update the policy document and make sure all repos have the vulnerability reporting feature enabled (including new repos).

cc @open-telemetry/governance-committee @open-telemetry/technical-committee

@yurishkuro
Copy link
Member

PR to the policy attached.

@yurishkuro
Copy link
Member

I enabled "Private vulnerability reporting" on all repos. Wish GitHub would have org-level settings that would override individual repo defaults.

@yurishkuro
Copy link
Member

yurishkuro commented Jul 14, 2023

turns out GitHub does support bulk updates of security settings, but the vulnerability reporting is not one of them, perhaps because it itself is in beta: https://docs.github.com/en/enterprise-cloud@latest/code-security/security-overview/enabling-security-features-for-multiple-repositories

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
spec:miscellaneous For issues that don't match any other spec label
Projects
None yet
Development

No branches or pull requests

3 participants