opensearch-project / opensearch-project/.github

[PROPOSAL] Define expectations around staffing of opensearch-security@amazon.com

Open
#95 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
41
Forks
74
Avg merge
3d 19h
Merged PRs (30d)
1

Description

Let's add some language to our SECURITY.md file around expectations for how the security issues mailbox will be staffed for the project.

Coming from this comment thread on the PR documenting the security issue response process:

how is the email address staffed? is it being monitored 24/7 or only during business hours in a specific location (e.g. US)?
is this internally a mailing list (i.e. you could eventually add non-AWS employees to the security maintainers) or is it a shared mailbox (i.e. only AWS employees can be added to it)?
[...]
maybe no specific commitment is needed, but it'd be good to know whether it can happen that all people with access to the mail address can be on vacation on the same time (think public holiday, etc.) or whether it'd be reasonable to expect a "we got your report and will be looking into it in the next few days and then get back to you" answer within 1-2 business days (thinking of the "we'll update you in 5 business days" emails from AWS security which they seem to be happy to send for several weeks in a row 🙄)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review SECURITY.md and the linked PR discussion to understand the existing security issue response process and the unanswered staffing questions. Document the agreed expectations for monitoring and response availability in SECURITY.md; the work is done when the mailbox staffing model and response expectations are clearly stated.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.