qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] QEMU CII Best Practices record
@ 2017-10-13 13:25 Daniel P. Berrange
  2017-10-23 17:31 ` Stefan Hajnoczi
  2017-10-23 17:55 ` Peter Maydell
  0 siblings, 2 replies; 6+ messages in thread
From: Daniel P. Berrange @ 2017-10-13 13:25 UTC (permalink / raw)
  To: qemu-devel

Many projects these days are recording progress wrt CII best practices
for FLOOS projects. I filled out a record for QEMU:

  https://bestpractices.coreinfrastructure.org/projects/1309

I only looked at the 'Passing' criteria, not considered the 'Silver' and
'Gold' criteria. So if anyone else wants to contribute, register an
account there and tell me the username whereupon I can add you as a
collaborator.

Two items I don't think QEMU achieves for the basic "Passing" criteria

 -  The release notes MUST identify every publicly known vulnerability
    that is fixed in each new release.

    I don't see a list of CVEs mentioned in our release Changelogs or
    indeed a historic list of CVEs anywhere even outside the release
    notes ?

 - It is SUGGESTED that if the software produced by the project includes
   software written using a memory-unsafe language (e.g., C or C++), then
   at least one dynamic tool (e.g., a fuzzer or web application scanner)
   be routinely used in combination with a mechanism to detect memory
   safety problems such as buffer overwrites.

   NB this is not 'coverity' which falls under the 'static anlaysis'
   group. I'm unclear if anyone in the community does regular fuzzing
   or analysis with ASAN & equiv ?

If i'm wrong just say....

There's many questions under Silver/Gold level we likely don't meet and
some of them start to get quiet opinionated about the way a project
should be run, so IMHO its not unreasonable to say we're not going to aim
for perfection in this respect.

Regards,
Daniel
-- 
|: https://berrange.com      -o-    https://www.flickr.com/photos/dberrange :|
|: https://libvirt.org         -o-            https://fstop138.berrange.com :|
|: https://entangle-photo.org    -o-    https://www.instagram.com/dberrange :|

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2017-10-24  8:12 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-10-13 13:25 [Qemu-devel] QEMU CII Best Practices record Daniel P. Berrange
2017-10-23 17:31 ` Stefan Hajnoczi
2017-10-23 17:55 ` Peter Maydell
2017-10-24  7:42   ` Daniel P. Berrange
2017-10-24  7:46     ` Daniel P. Berrange
2017-10-24  8:12       ` Peter Maydell

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).