Conversation
| Risk is determined through internal scoring using CVSSv3.1 (https://www.first.org/cvss/calculator/3.1). | ||
|
|
||
| ### Security Advisories | ||
| Notifications and descriptions of security incidents are available here. |
There was a problem hiding this comment.
To be clear, at loss of a better solution, are you recommended that the list of Security Advisories related to Solid will be currated manually as a list:
- inside this present document; or;
- in an external
security-advisories.md?
I would probably have a slight preference for the latter.
security.md
Outdated
| info@solidproject.org | ||
| Submit an issue to our team on github |
There was a problem hiding this comment.
I'm not sure which repo these issues belong on.
| info@solidproject.org | |
| Submit an issue to our team on github | |
| Please submit any issues to [our team on github](needs_the_repo/issues/), or email <info@solidproject.org>. |
security.md
Outdated
| * Accessing, or attempting to access, data or information that does not belong to you | ||
| * Destroying or corrupting, or attempting to destroy or corrupt, data or information that does not belong to you | ||
|
|
||
| Software often contains third party or open source libraries and binaries. Prior to submitting a request to validate how a security issue in third party components may impact Solid, please review the section on third party CVE handling. |
There was a problem hiding this comment.
Software often contains third party or open source libraries and binaries. Prior to submitting a request to validate how a security issue in third party components may impact Solid, please review the section on Handling Third Party CVE (Common Vulnerabilities and Exposures).
| Risk is determined through internal scoring using CVSSv3.1 (https://www.first.org/cvss/calculator/3.1). | ||
|
|
||
| ### Security Advisories | ||
| Notifications and descriptions of security incidents are available here. |
There was a problem hiding this comment.
| Notifications and descriptions of security incidents are available here. | |
| Notifications and descriptions of security incidents are available [here](needs_a_link_to_document_or_directory). |
| ### Security Advisories | ||
| Notifications and descriptions of security incidents are available here. | ||
|
|
||
| Security Advisories and other security content are provided on an "as is" basis and do not imply any kind of guarantee or warranty. Your use of the information in these publications or linked material is at your own risk. Inrupt reserves the right to change or update this content without notice at any time. |
There was a problem hiding this comment.
Inrupt.com? Or solidproject.org? This document is starting to exhibit a split personality...
Co-authored-by: Matthieu Bosquet <matthieubosquet@gmail.com>
Co-authored-by: Matthieu Bosquet <matthieubosquet@gmail.com>
Co-authored-by: Ted Thibodeau Jr <tthibodeau@openlinksw.com>
Co-authored-by: Ted Thibodeau Jr <tthibodeau@openlinksw.com>
new page to explain a process how to report vulnerabilities and what advisories will look like