community icon indicating copy to clipboard operation
community copied to clipboard

Security response team rotation is outdated

Open aliok opened this issue 2 years ago • 11 comments

Related docs:

  • https://github.com/knative/community/blob/main/SECURITY.md
  • https://github.com/knative/community/blob/main/working-groups/security/disclosure.md
  • https://github.com/knative/community/blob/main/working-groups/security/responding.md

VMT rotation is outdated: https://github.com/knative/community/blob/main/working-groups/security/vmt.rotation (not sure where this is used)

Also, can we verify that [email protected] is still working with recipients still active in the project?

aliok avatar Jul 28 '23 14:07 aliok

Ah, and, it might be good to list publicly who receives mails sent to that email address.

aliok avatar Jul 28 '23 14:07 aliok

cc @knative/technical-oversight-committee

aliok avatar Jul 28 '23 14:07 aliok

@evankanderson @davidhadas

psschwei avatar Jul 28 '23 15:07 psschwei

I believe that the alias is still working.

The rotation was used with https://knative.party/, but since we only had one lead and no other volunteers, it had just been me for a while. It would be great to get a larger set of particpants (maybe TOC?)

evankanderson avatar Jul 31 '23 16:07 evankanderson

We didn't sign up for upstream early notifications -- I think that was on julz@'s plate, and the reduction of interest and capacity meant that dropped by the wayside

evankanderson avatar Jul 31 '23 16:07 evankanderson

Verified that [email protected] is still working

evankanderson avatar Jul 31 '23 16:07 evankanderson

/assign @davidhadas

dprotaso avatar Jan 17 '24 15:01 dprotaso

Is there a requirement to have a vmt.rotation file? Is this documented anywhere? If not, I suggest to drop this page.

We do need to make sure we have the vulnerability procedure well documented and updated. Lets do another review of disclosure.md and responding.md

davidhadas avatar Jan 17 '24 15:01 davidhadas

Q from @dprotaso: is the TOC on the [email protected] mailing list?

davidhadas avatar Jan 17 '24 15:01 davidhadas

Q from @dprotaso: is the TOC on the [email protected] mailing list?

It is not currently -- we could add them if desired.

evankanderson avatar Jan 29 '24 17:01 evankanderson