opensearch-project / opensearch-project/.github
[PROPOSAL] Define expectations around staffing of opensearch-security@amazon.com
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 41
- Forks
- 74
- Avg merge
- 3d 19h
- Merged PRs (30d)
- 1
Description
Let's add some language to our SECURITY.md file around expectations for how the security issues mailbox will be staffed for the project.
Coming from this comment thread on the PR documenting the security issue response process:
how is the email address staffed? is it being monitored 24/7 or only during business hours in a specific location (e.g. US)?
is this internally a mailing list (i.e. you could eventually add non-AWS employees to the security maintainers) or is it a shared mailbox (i.e. only AWS employees can be added to it)?
[...]
maybe no specific commitment is needed, but it'd be good to know whether it can happen that all people with access to the mail address can be on vacation on the same time (think public holiday, etc.) or whether it'd be reasonable to expect a "we got your report and will be looking into it in the next few days and then get back to you" answer within 1-2 business days (thinking of the "we'll update you in 5 business days" emails from AWS security which they seem to be happy to send for several weeks in a row 🙄)
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review SECURITY.md and the linked PR discussion to understand the existing security issue response process and the unanswered staffing questions. Document the agreed expectations for monitoring and response availability in SECURITY.md; the work is done when the mailbox staffing model and response expectations are clearly stated.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100