summaryrefslogtreecommitdiff
path: root/contributors/devel/security-release-process.md
AgeCommit message (Collapse)Author
2018-04-26update to remove 1.10 outdated linksZach Arnold
2017-12-22Tombstone security-release-process.md, point to sig-releaseAaron Crickenberger
The doc was copied over to sig-release a while ago but then that copy was never made authoritative
2017-12-15security-release-process: remove PGP requirementJess Frazelle
Signed-off-by: Jess Frazelle <acidburn@microsoft.com>
2017-11-17Merge pull request #498 from philips/security-process-announce-timeKubernetes Submit Queue
Automatic merge from submit-queue. devel: add recommended time to release process
2017-11-03removed autogenerated munge analytics from filesguineveresaenger
2017-10-16Security Release: add copy about other upstream timelinesJess Frazelle
Signed-off-by: Jess Frazelle <acidburn@microsoft.com>
2017-10-05Security Process: Add Distributors List ProcessJess Frazelle
Signed-off-by: Jess Frazelle <acidburn@microsoft.com>
2017-08-23Update jess' emailJess Frazelle
Signed-off-by: Jess Frazelle <acidburn@google.com>
2017-07-12s/Tim St\. Clair/Tim Allclair/gTim Allclair
2017-07-12Add public key for liggittJordan Liggitt
2017-05-20Fix typoDan Kohn
Note the self-referential bug.
2017-04-01devel: add recommended time to release processBrandon Philips
I am simply copying Golang which has selected a reasonable time: https://groups.google.com/forum/#!topic/golang-announce/YOqTqcJtiJI
2017-03-14add gpg keyJess Frazelle
Signed-off-by: Jess Frazelle <acidburn@google.com>
2017-03-05contributors: security release process: links and severityBrandon Philips
- Add links to mailing lists - Make 4.0 CVSS low severity
2017-03-03contributors: devel: more security-release-process feedbackBrandon Philips
Address all outstanding feedback.
2017-01-29security-release-process: cleanup the overall processBrandon Philips
Make the language much easier to read from beginning to end. And make everyone's role easier to understand by giving people explicit role names.
2017-01-29security-release-process: add release managersBrandon Philips
The release managers should be on the list as they are going to be the central point of coordination for testing, release, and communication.
2017-01-29security-release-process: remove mjg59 from PSTBrandon Philips
mjg59 has changed his role and has requested to be removed from the responsiblity of the PST.
2017-01-29docs: devel: add security release processBrandon Philips
After the v1.4.3 release I know we are all thinking about the security disclosure and response plan for Kubernetes. I think we need to document some internal processes, external communication templates/process, and improve the disclosure systems. This document is based on discussion and a Google doc on SIG Auth: https://groups.google.com/forum/#!topic/kubernetes-sig-auth/Xq2f8bWCNDM **Known issues** - We haven't specified a way to cycle the Product Security Team; but we need this process deployed quickly as our current process isn't working. I will put a deadline of March 1st 2017 to sort that. Tracking issue: https://github.com/kubernetes/kubernetes/issues/35462