summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJess Frazelle <acidburn@microsoft.com>2017-10-16 14:49:11 -0400
committerJess Frazelle <acidburn@microsoft.com>2017-10-16 14:49:15 -0400
commitbf3ea34e0f17c14972184fdbde24d444eff33e21 (patch)
treed36d4a22b50ebbcb9fb732e613fe688bf60349d7
parentec2062efedce54c314714b381fd22e528a90126f (diff)
Security Release: add copy about other upstream timelines
Signed-off-by: Jess Frazelle <acidburn@microsoft.com>
-rw-r--r--contributors/devel/security-release-process.md12
1 files changed, 10 insertions, 2 deletions
diff --git a/contributors/devel/security-release-process.md b/contributors/devel/security-release-process.md
index 521c215f..8f47e1eb 100644
--- a/contributors/devel/security-release-process.md
+++ b/contributors/devel/security-release-process.md
@@ -40,11 +40,19 @@ If possible the PST will ask the person making the public report if the issue ca
## Patch, Release, and Public Communication
-For each vulnerability a member of the PST will volunteer to lead coordination with the Fix Team, Release Managers and is responsible for sending disclosure emails to the rest of the community. This lead will be referred to as the Fix Lead.
+For each vulnerability a member of the PST will volunteer to lead coordination
+with the Fix Team, Release Managers and is responsible for sending disclosure
+emails to the rest of the community. This lead will be referred to as the Fix Lead.
The role of Fix Lead should rotate round-robin across the PST.
-All of the timelines below are suggestions and assume a Private Disclosure. The Fix Lead drives the schedule using their best judgment based on severity, development time, and release manager feedback. If the Fix Lead is dealing with a Public Disclosure all timelines become ASAP.
+All of the timelines below are suggestions and assume a Private Disclosure.
+The Fix Lead drives the schedule using their best judgment based on severity,
+development time, and release manager feedback. If the Fix Lead is dealing with
+a Public Disclosure all timelines become ASAP. If the fix relies on another
+upstream project's disclosure timeline, that will adjust the process as well.
+We will work with the upstream project to fit their timeline and best protect
+our users.
### Fix Team Organization