1- # Hyperledger Firefly , an LF Decentralized Trust Project Security Policy
1+ # Hyperledger FireFly , an LF Decentralized Trust Project Security Policy
22
33[ LF Decentralized Trust Security Policy ] : https://lf-decentralized-trust.github.io/governance/governing-documents/security
44
55## About this document
66
7- This document defines how security vulnerability reporting is handled in Hyperledger Firefly , an LF Decentralized Trust Project.
7+ This document defines how security vulnerability reporting is handled in Hyperledger FireFly , an LF Decentralized Trust Project.
88The approach aligns with the [ LF Decentralized Trust Security Policy] . Please
9- review that document to understand the basis of the security reporting for Hyperledger Firefly .
9+ review that document to understand the basis of the security reporting for Hyperledger FireFly .
1010
1111This vulnerability policy borrows heavily from the
1212recommendations of the OpenSSF Vulnerability Disclosure working group. For
1313up-to-date information on the latest recommendations related to vulnerability
1414disclosures, please visit the [ GitHub of that working
1515group] ( https://github.com/ossf/wg-vulnerability-disclosures ) .
1616
17- If you are already familiar with the security policies of Hyperledger Firefly , and
17+ If you are already familiar with the security policies of Hyperledger FireFly , and
1818ready to report a vulnerability, please jump to [ Report Intakes] ( #report-intakes ) .
1919
2020## Outline
2121
2222This document has the following sections:
2323
24- - [ Hyperledger Firefly Security Policy] ( #project-an-lf-decentralized-trust-project-security-policy )
24+ - [ Hyperledger FireFly Security Policy] ( #project-an-lf-decentralized-trust-project-security-policy )
2525 - [ Instructions] ( #instructions )
2626 - [ About this document] ( #about-this-document )
2727 - [ Outline] ( #outline )
@@ -43,20 +43,22 @@ vulnerability disclosure policy explains how this process functions from the
4343perspective of the project.
4444
4545This vulnerability disclosure policy explains the rules and guidelines for
46- Hyperledger Firefly . It is intended to act as both a reference for
46+ Hyperledger FireFly . It is intended to act as both a reference for
4747outsiders–including both bug reporters and those looking for information on the
4848project’s security practices–as well as a set of rules that maintainers and
4949contributors have agreed to follow.
5050
5151## Security Team
5252
53- The current Hyperledger Firefly security team is:
53+ The current Hyperledger FireFly security team is:
5454
55- | Name | Email ID | Discord ID | Area/Specialty |
56- | ---------------- | ------------------------ | ---------- | ---------------|
57- | Enrique Lacal
| [email protected] | @enriquel8 | Everything
| 55+ | Name | Email ID | Discord ID | Area/Specialty |
56+ | ---------------- | ----------------------------------- | ---------------- | ----------------- |
57+ | Enrique Lacal
| [email protected] | @enriquel8 | FireFly Core
| 58+ | Simon Gellis
| [email protected] | @SonicSwordcane | Cardano connector
| 59+ | Alexey Semenyuk
| [email protected] | @alexey_semenyuk
| Tezos connector
| 5860
59- The security team for Hyperledger Firefly must include at least three project
61+ The security team for Hyperledger FireFly must include at least three project
6062Maintainers that agree to carry out the following duties and responsibilities.
6163Members are added and removed from the team via approved Pull Requests to this
6264repository. For additional background into the role of the security team, see
@@ -112,7 +114,7 @@ with invited participants added to the discussion.
112114
113115## Report Intakes
114116
115- Hyperledger Firefly has the following ways to submit security
117+ Hyperledger FireFly has the following ways to submit security
116118vulnerabilities. While the security team members will do their best to
117119respond to bugs disclosed in all possible ways, it is encouraged for bug
118120finders to report through the following approved channels:
@@ -133,18 +135,18 @@ infrastructure in GitHub.
133135
134136## CNA/CVE Reporting
135137
136- Hyperledger Firefly maintains a list of ** Common Vulnerabilities and Exposures
138+ Hyperledger FireFly maintains a list of ** Common Vulnerabilities and Exposures
137139(CVE)** and uses GitHub as its ** CVE numbering authority (CNA)** for issuing
138140CVEs.
139141
140142## Embargo List
141143
142- Hyperledger Firefly does ** NOT** currently maintain a private embargo list.
144+ Hyperledger FireFly does ** NOT** currently maintain a private embargo list.
143145
144146If you wish to be added to the embargo list, please email the [ LF Decentralized Trust Foundation security
145147mailing list
] ( mailto:[email protected] ) , including the project name
146- (Hyperledger Firefly ) and reason for being added to the embargo list. Requests
147- will be assessed by the Hyperledger Firefly security team in conjunction with the
148+ (Hyperledger FireFly ) and reason for being added to the embargo list. Requests
149+ will be assessed by the Hyperledger FireFly security team in conjunction with the
148150appropriate LF Decentralized Trust Staff, and a decision will be made to accommodate or not
149151the request.
150152
@@ -154,13 +156,13 @@ Policy](https://lf-decentralized-trust.github.io/governance/governing-documents/
154156
155157## (GitHub) Security Advisories
156158
157- Hyperledger Firefly uses GitHub Security Advisories to manage the public
159+ Hyperledger FireFly uses GitHub Security Advisories to manage the public
158160disclosure of security vulnerabilities.
159161
160162## Private Patch Deployment Infrastructure
161163
162164In creating patches and new releases that address security vulnerabilities,
163- Hyperledger Firefly uses the private development features of GitHub for security
165+ Hyperledger FireFly uses the private development features of GitHub for security
164166vulnerabilities. GitHub has [ extensive
165167documentation] ( https://docs.github.com/en/code-security/security-advisories/repository-security-advisories )
166168about these features.
0 commit comments