Skip to content

Unify vocabulary usage between vuln management and handling#26

Open
mrybczyn wants to merge 2 commits intoorcwg:mainfrom
mrybczyn:vulnerability-management
Open

Unify vocabulary usage between vuln management and handling#26
mrybczyn wants to merge 2 commits intoorcwg:mainfrom
mrybczyn:vulnerability-management

Conversation

@mrybczyn
Copy link
Copy Markdown

"Vulnerability handling" is a term frequently used to signify the process of resolving the vulnerability, while the disclosure is another process. This document covers both, so we prefer to use the general term "vulnerability management" in the general case.

"Vulnerability handling" is a term frequently used to signify the process of
resolving the vulnerability, while the disclosure is another process. This document
covers both, so we prefer to use the general term "vulnerability management"
in the general case.

Signed-off-by: Marta Rybczynska <marta.rybczynska@eclipse-foundation.org>
@rjb4standards
Copy link
Copy Markdown

100% agree - Vulnerability Management covers both vulnerability handling, i.e. coordinated vulnerability disclosure processing by a vendor and vulnerability disclosure reporting from a vendor to a consumer of a confirmed vulnerability..

@tobie
Copy link
Copy Markdown
Contributor

tobie commented Apr 22, 2025

Suggest fixing the README in the same PR too.

@mrybczyn
Copy link
Copy Markdown
Author

Suggest fixing the README in the same PR too.

Well spotted! I'm updating the PR

Unify vocabulary between vulnerability management (preferred) and handling
(more specific).

Signed-off-by: Marta Rybczynska <marta.rybczynska@eclipse-foundation.org>
@mrybczyn
Copy link
Copy Markdown
Author

mrybczyn commented May 7, 2025

@mbarbero @tobie PR updated

@mrybczyn mrybczyn changed the title spec.md: unify vocabulary usage between vuln management and handling Unify vocabulary usage between vuln management and handling May 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants