Skip to content

Publish wolfSSL Security Policy and Vulnerability Report Template#10284

Open
ColtonWilley wants to merge 2 commits intowolfSSL:masterfrom
ColtonWilley:security_policy_and_report_template
Open

Publish wolfSSL Security Policy and Vulnerability Report Template#10284
ColtonWilley wants to merge 2 commits intowolfSSL:masterfrom
ColtonWilley:security_policy_and_report_template

Conversation

@ColtonWilley
Copy link
Copy Markdown
Contributor

Description

Publishes wolfSSL's external security policy and a structured vulnerability report template.

  • SECURITY-POLICY.md — external-facing policy: CVE-filing criterion, severity tiers, categories addressed as hardening rather than CVEs, coordinated-disclosure practice, credit. Deliberately terse and discretionary, matching OpenSSL and Mbed TLS practice.
  • SECURITY-REPORT-TEMPLATE.md — structured report template; use is mandatory for CVE consideration. Requires reachability trace, attacker model, working PoC, and a related-work check against open PRs.
  • .github/SECURITY.md — replaces the short stub with a pointer to the two new documents. All reports route to support@wolfssl.com.

Add SECURITY-POLICY.md and SECURITY-REPORT-TEMPLATE.md at the repository
root and replace the .github/SECURITY.md stub with a short pointer.

SECURITY-POLICY.md is intentionally terse and discretionary, matching
OpenSSL and Mbed TLS practice. It states the CVE-filing criterion,
severity tiers, categories not considered CVE-eligible, coordinated-
disclosure practice, and credit.

SECURITY-REPORT-TEMPLATE.md is a structured report template whose use is
mandatory for CVE consideration. It requires a reachability trace,
attacker model, working proof-of-concept, and a related-work check
against open pull requests and recent commits.

All reports route to support@wolfssl.com.
Related Work Check is a triage prerequisite and belongs with the other
due-diligence sections, not at the end after disclosure coordination.
Previous sections 8-11 shift to 9-12. Content unchanged; no internal
cross-references point to the shifted sections.
@github-actions
Copy link
Copy Markdown

MemBrowse Memory Report

No memory changes detected for:

@ColtonWilley
Copy link
Copy Markdown
Contributor Author

Jenkins retest this please

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants