Consider abbreviated security release process for issues found on master (not yet in any release)
Open
area/community
area/security
help wanted
- Dominant language
- C++
- Stars
- 28.9k
- Forks
- 5.6k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 437
Description
Envoy has a security release process. However, it doesn't fit well for issues found on master, and not yet in any release.
We should consider creating an abbreviated process for notifying interested parties, and releasing the fix in a shorter window of time.
Some discussion on the issue: https://github.com/envoyproxy/envoy/pull/11148#discussion_r423221002
Contributor guide
Assessment
This issue has not been assessed yet.