Skip to content

[Security Policy]: Enhancement proposals to Open-CMSIS-Pack security Policy #293

@iomint

Description

@iomint

Description

Here two proposals related to the newly introduced Open-CMSIS-Pack security policy
The page mainly refers to the GitHub's private vulnerability reporting guidelines that remain rather generic as well as the vulnerability management section. I suggest considering as reference the security policy of trustedfimware.org project and more especially the Security Incident Handling Process section related to "disclosure" that figures out a description of the different steps with indicative timeline; this section also describes a communication process with a concept of "Especially Sensitive Stakeholders (ESSes)" that I also suggest considering for Open-CMSIS-Pack.

Is this request a Security Requirement?

  • Yes

Priority

Medium

Related Issues (Optional)

No response

Additional Notes (Optional)

No response

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

Projects

Status

Backlog

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions