eclipse-score / eclipse-score/score

Improvement: Setup Tools/Documentation for vulnerability Management

Open
#2,640 0 comments 0 reactions 4 assignees Claimed by @CryptoNutcase View on GitHub
documentation
Dominant language
Starlark
Stars
109
Forks
105
Avg merge
1d 9h
Merged PRs (30d)
21

Description

### What

https://www.eclipse.org/security/ describes Security at the Eclipse Foundation, Consider

Report a vulnerability
To report a security vulnerability in an Eclipse Foundation Project, first, check the project’s repository for a SECURITY.md file and follow its instructions. If none exist, you can email the Eclipse Foundation Security Team at [security@eclipse-foundation.org](mailto:security@eclipse-foundation.org) or use the [dedicated issue tracker](https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/new?issuable_template=new_vulnerability).

For the principles under which the Eclipse Foundation manages the reporting, management, discussion, and disclosure of vulnerabilities discovered in Eclipse software, refer to the [Eclipse Foundation Security Policy](https://www.eclipse.org/security/policy/).

For more details on how we handle vulnerability reports, see the [Eclipse Project Handbook](https://www.eclipse.org/projects/handbook/).

and https://eclipse-csi.github.io/security-handbook/index.html

Actions:

- [ ] Create SECURITY.md with proper documentation, links to existing document to enable user easily to report a vulnerability
- [ ] Check Eclipse Security Handbook for Developer
- [ ] Check Eclipse Security Handbook for Project
- [ ] Check Eclipse Security Handbook for Vulnerability Management
- [ ] Check Eclipse Security Handbook for SBOM

### How

Create SECURITY.md and other documentation, configurations to manage security in S-CORE

### Estimates for realization

1 month

### Category

- [ ] Affects Detailed Design

### Requirements / Architecture

- [x] Requirements / Architecture are not affected by this change?

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.