Skip to content

Update security policy for private vulnerability reporting - #5555

Merged
pfi79 merged 1 commit into
mainfrom
secpol-update
Sep 6, 2026
Merged

Update security policy for private vulnerability reporting#5555
pfi79 merged 1 commit into
mainfrom
secpol-update

Conversation

@ryjones

@ryjones ryjones commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

The policy gave security@hyperledger.org as the email intake and linked to Defect Response on the retired Hyperledger wiki. It also pointed at the security advisories index rather than the form used to open a report.

Rewrite it along the lines of the policy already in fabric-gateway:

  • Align with the LF Decentralized Trust security vulnerability disclosure policy and link to it as the governing document.
  • Lead with GitHub private vulnerability reporting, linking to the new advisory form for this repository, and state plainly that issues, discussions, and pull requests are not the place for a report.
  • Give security@lists.lfdecentralizedtrust.org as the email intake, which LF Decentralized Trust requires every project to accept.
  • Describe what a useful report contains, what a reporter should expect in return including the two business day acknowledgement the governing policy sets, and how vulnerabilities in dependencies are handled.

Type of change

  • Bug fix
  • New feature
  • Improvement (improvement to code, performance, etc)
  • Test update
  • Documentation update

Description

Additional details

Related issues

The policy gave security@hyperledger.org as the email intake and linked
to Defect Response on the retired Hyperledger wiki. It also pointed at
the security advisories index rather than the form used to open a report.

Rewrite it along the lines of the policy already in fabric-gateway:

- Align with the LF Decentralized Trust security vulnerability disclosure
  policy and link to it as the governing document.
- Lead with GitHub private vulnerability reporting, linking to the new
  advisory form for this repository, and state plainly that issues,
  discussions, and pull requests are not the place for a report.
- Give security@lists.lfdecentralizedtrust.org as the email intake, which
  LF Decentralized Trust requires every project to accept.
- Describe what a useful report contains, what a reporter should expect
  in return including the two business day acknowledgement the governing
  policy sets, and how vulnerabilities in dependencies are handled.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Ry Jones <ry@linux.com>
@ryjones
ryjones marked this pull request as ready for review September 6, 2026 15:50
@ryjones
ryjones requested a review from a team as a code owner September 6, 2026 15:50
Comment thread SECURITY.md

## What to expect

- We will acknowledge receipt of your report within 2 business days.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm confused about setting specific deadlines. Why specify them? And if this is not done within 2 days, then what?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is the policy from the LFDT TAC

@pfi79
pfi79 merged commit 6ac1579 into main Sep 6, 2026
26 checks passed
@mergify

mergify Bot commented Sep 6, 2026

Copy link
Copy Markdown

Tick the box to add this pull request to the merge queue (same as @mergifyio queue).

  • Queue this pull request

@ryjones
ryjones deleted the secpol-update branch September 6, 2026 16:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants