* [bluez/bluez] 79918b: SECURITY: Add top-level security doc
@ 2026-08-28 21:29 hadess
0 siblings, 0 replies; only message in thread
From: hadess @ 2026-08-28 21:29 UTC (permalink / raw)
To: linux-bluetooth
Branch: refs/heads/master
Home: https://github.com/bluez/bluez
Commit: 79918b87dccdb804c1fe338fe8fdfcb77a0e8293
https://github.com/bluez/bluez/commit/79918b87dccdb804c1fe338fe8fdfcb77a0e8293
Author: Bastien Nocera <hadess@hadess.net>
Date: 2026-08-28 (Fri, 28 Aug 2026)
Changed paths:
M Makefile.am
M README
A SECURITY.md
Log Message:
-----------
SECURITY: Add top-level security doc
This will replace the existing documentation written 5 years ago to take
into account the new tools and the new rules around dealing with
security issues.
The new workflow replaces email-based reporting with the GitHub security
advisory tools, explains the CVE ID assignment process, and places strict
limits on the amount of work that can be demanded from BlueZ developers.
It is customary in 2026 to have a top-level SECURITY.md file which
explains the vulnerability workflow.
Commit: e8141342284be2a52e16565b96b513ebe1297d84
https://github.com/bluez/bluez/commit/e8141342284be2a52e16565b96b513ebe1297d84
Author: Bastien Nocera <hadess@hadess.net>
Date: 2026-08-28 (Fri, 28 Aug 2026)
Changed paths:
R doc/security-bugs.rst
Log Message:
-----------
doc: Remove obsolete security-bugs.rst
Compare: https://github.com/bluez/bluez/compare/49592cbc1416...e8141342284b
To unsubscribe from these emails, change your notification settings at https://github.com/bluez/bluez/settings/notifications
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-28 21:30 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-28 21:29 [bluez/bluez] 79918b: SECURITY: Add top-level security doc hadess
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox