From 4b32f61d6acc70cac97016d4b8463bbf254356d7 Mon Sep 17 00:00:00 2001 From: Marta Rybczynska <marta.rybczynska@huawei.com> Date: Wed, 29 Sep 2021 08:55:32 +0200 Subject: [PATCH] cve_policy: add link to OpenSSF vulnerability disclosure work Add a link to newly released OpenSSF Vulnerability Disclosure WG guide to disclosure for OSS projects. Signed-off-by: Marta Rybczynska <marta.rybczynska@huawei.com> --- security/cve_policy.rst | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/security/cve_policy.rst b/security/cve_policy.rst index 5c7d3ec..5d54a8d 100644 --- a/security/cve_policy.rst +++ b/security/cve_policy.rst @@ -248,6 +248,8 @@ Acknowledgements This process was inspired by the `OSS vulnerability guide <https://github.com/google/oss-vulnerability-guide/blob/main/guide.md>`__, -`OpenSSF vulnerability-disclosures WG +the `OpenSSF Vulnerability Disclosure WG guide to disclosure for OSS projects +<https://github.com/ossf/oss-vulnerability-guide/blob/main/guide.md>`__, +other work from the `OpenSSF vulnerability-disclosures WG <https://github.com/ossf/wg-vulnerability-disclosures>`__, `Zephyr project security policy <https://www.zephyrproject.org/security/>`__. -- GitLab