Skip to content

Commit 77c5d0e

Browse files
committed
Add team
Signed-off-by: Aliaksei Semianiuk [email protected]
1 parent 041cd19 commit 77c5d0e

File tree

1 file changed

+20
-18
lines changed

1 file changed

+20
-18
lines changed

SECURITY.md

Lines changed: 20 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -1,27 +1,27 @@
1-
# Hyperledger Firefly, an LF Decentralized Trust Project Security Policy
1+
# Hyperledger FireFly, an LF Decentralized Trust Project Security Policy
22

33
[LF Decentralized Trust Security Policy]: https://lf-decentralized-trust.github.io/governance/governing-documents/security
44

55
## About this document
66

7-
This document defines how security vulnerability reporting is handled in Hyperledger Firefly, an LF Decentralized Trust Project.
7+
This document defines how security vulnerability reporting is handled in Hyperledger FireFly, an LF Decentralized Trust Project.
88
The approach aligns with the [LF Decentralized Trust Security Policy] . Please
9-
review that document to understand the basis of the security reporting for Hyperledger Firefly.
9+
review that document to understand the basis of the security reporting for Hyperledger FireFly.
1010

1111
This vulnerability policy borrows heavily from the
1212
recommendations of the OpenSSF Vulnerability Disclosure working group. For
1313
up-to-date information on the latest recommendations related to vulnerability
1414
disclosures, please visit the [GitHub of that working
1515
group](https://github.com/ossf/wg-vulnerability-disclosures).
1616

17-
If you are already familiar with the security policies of Hyperledger Firefly, and
17+
If you are already familiar with the security policies of Hyperledger FireFly, and
1818
ready to report a vulnerability, please jump to [Report Intakes](#report-intakes).
1919

2020
## Outline
2121

2222
This document has the following sections:
2323

24-
- [Hyperledger Firefly Security Policy](#project-an-lf-decentralized-trust-project-security-policy)
24+
- [Hyperledger FireFly Security Policy](#project-an-lf-decentralized-trust-project-security-policy)
2525
- [Instructions](#instructions)
2626
- [About this document](#about-this-document)
2727
- [Outline](#outline)
@@ -43,20 +43,22 @@ vulnerability disclosure policy explains how this process functions from the
4343
perspective of the project.
4444

4545
This vulnerability disclosure policy explains the rules and guidelines for
46-
Hyperledger Firefly. It is intended to act as both a reference for
46+
Hyperledger FireFly. It is intended to act as both a reference for
4747
outsiders–including both bug reporters and those looking for information on the
4848
project’s security practices–as well as a set of rules that maintainers and
4949
contributors have agreed to follow.
5050

5151
## Security Team
5252

53-
The current Hyperledger Firefly security team is:
53+
The current Hyperledger FireFly security team is:
5454

55-
| Name | Email ID | Discord ID | Area/Specialty |
56-
| ---------------- | ------------------------ | ---------- | ---------------|
57-
| Enrique Lacal | [email protected] | @enriquel8 | Everything |
55+
| Name | Email ID | Discord ID | Area/Specialty |
56+
| ---------------- | ----------------------------------- | ---------------- | ----------------- |
57+
| Enrique Lacal | [email protected] | @enriquel8 | FireFly Core |
58+
| Simon Gellis | [email protected] | @SonicSwordcane | Cardano connector |
59+
| Alexey Semenyuk | [email protected] | @alexey_semenyuk | Tezos connector |
5860

59-
The security team for Hyperledger Firefly must include at least three project
61+
The security team for Hyperledger FireFly must include at least three project
6062
Maintainers that agree to carry out the following duties and responsibilities.
6163
Members are added and removed from the team via approved Pull Requests to this
6264
repository. For additional background into the role of the security team, see
@@ -112,7 +114,7 @@ with invited participants added to the discussion.
112114

113115
## Report Intakes
114116

115-
Hyperledger Firefly has the following ways to submit security
117+
Hyperledger FireFly has the following ways to submit security
116118
vulnerabilities. While the security team members will do their best to
117119
respond to bugs disclosed in all possible ways, it is encouraged for bug
118120
finders to report through the following approved channels:
@@ -133,18 +135,18 @@ infrastructure in GitHub.
133135

134136
## CNA/CVE Reporting
135137

136-
Hyperledger Firefly maintains a list of **Common Vulnerabilities and Exposures
138+
Hyperledger FireFly maintains a list of **Common Vulnerabilities and Exposures
137139
(CVE)** and uses GitHub as its **CVE numbering authority (CNA)** for issuing
138140
CVEs.
139141

140142
## Embargo List
141143

142-
Hyperledger Firefly does **NOT** currently maintain a private embargo list.
144+
Hyperledger FireFly does **NOT** currently maintain a private embargo list.
143145

144146
If you wish to be added to the embargo list, please email the [LF Decentralized Trust Foundation security
145147
mailing list](mailto:[email protected]), including the project name
146-
(Hyperledger Firefly) and reason for being added to the embargo list. Requests
147-
will be assessed by the Hyperledger Firefly security team in conjunction with the
148+
(Hyperledger FireFly) and reason for being added to the embargo list. Requests
149+
will be assessed by the Hyperledger FireFly security team in conjunction with the
148150
appropriate LF Decentralized Trust Staff, and a decision will be made to accommodate or not
149151
the request.
150152

@@ -154,13 +156,13 @@ Policy](https://lf-decentralized-trust.github.io/governance/governing-documents/
154156

155157
## (GitHub) Security Advisories
156158

157-
Hyperledger Firefly uses GitHub Security Advisories to manage the public
159+
Hyperledger FireFly uses GitHub Security Advisories to manage the public
158160
disclosure of security vulnerabilities.
159161

160162
## Private Patch Deployment Infrastructure
161163

162164
In creating patches and new releases that address security vulnerabilities,
163-
Hyperledger Firefly uses the private development features of GitHub for security
165+
Hyperledger FireFly uses the private development features of GitHub for security
164166
vulnerabilities. GitHub has [extensive
165167
documentation](https://docs.github.com/en/code-security/security-advisories/repository-security-advisories)
166168
about these features.

0 commit comments

Comments
 (0)