Linux bluetooth development
 help / color / mirror / Atom feed
* [bluez/bluez] 79918b: SECURITY: Add top-level security doc
@ 2026-08-28 21:29 hadess
  0 siblings, 0 replies; only message in thread
From: hadess @ 2026-08-28 21:29 UTC (permalink / raw)
  To: linux-bluetooth

  Branch: refs/heads/master
  Home:   https://github.com/bluez/bluez
  Commit: 79918b87dccdb804c1fe338fe8fdfcb77a0e8293
      https://github.com/bluez/bluez/commit/79918b87dccdb804c1fe338fe8fdfcb77a0e8293
  Author: Bastien Nocera <hadess@hadess.net>
  Date:   2026-08-28 (Fri, 28 Aug 2026)

  Changed paths:
    M Makefile.am
    M README
    A SECURITY.md

  Log Message:
  -----------
  SECURITY: Add top-level security doc

This will replace the existing documentation written 5 years ago to take
into account the new tools and the new rules around dealing with
security issues.

The new workflow replaces email-based reporting with the GitHub security
advisory tools, explains the CVE ID assignment process, and places strict
limits on the amount of work that can be demanded from BlueZ developers.

It is customary in 2026 to have a top-level SECURITY.md file which
explains the vulnerability workflow.


  Commit: e8141342284be2a52e16565b96b513ebe1297d84
      https://github.com/bluez/bluez/commit/e8141342284be2a52e16565b96b513ebe1297d84
  Author: Bastien Nocera <hadess@hadess.net>
  Date:   2026-08-28 (Fri, 28 Aug 2026)

  Changed paths:
    R doc/security-bugs.rst

  Log Message:
  -----------
  doc: Remove obsolete security-bugs.rst


Compare: https://github.com/bluez/bluez/compare/49592cbc1416...e8141342284b

To unsubscribe from these emails, change your notification settings at https://github.com/bluez/bluez/settings/notifications

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-28 21:30 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-28 21:29 [bluez/bluez] 79918b: SECURITY: Add top-level security doc hadess

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox