FOR DISCUSSION: a proposal to add Project's Security Team
Compare changes
+ 15
− 0
@@ -268,6 +268,21 @@ Projects are required to make a Project plan available to their community at the
Any Committer may propose a creation of a separate Project's Security Team to the PMC. If the PMC approves the proposal, all Committers vote on the proposal. The creation of a separate Project's Security Team requires consensus with no objections (only +1 or abstentions, no -1 votes). The same rule applies to the closing of a separate Project's Security Team.
The Project's Security Team must consist of at least two persons; at least one of them must be a Committer in the Project. A representative from the PMC of the project is recommended. The Project is free to elect non-Committers to the Project's Security Team, given that they have relevant security experience. The Project's PMC might decide on additional rules for the composition of the Project's Security Team.
The members of Project's Security Team must keep strict confidentiality of issues before they are resolved and released publicly. For resolution of a particular issue, they might bring in additional Committers or Contributors, or additional domain experts. Those contributors must adhere to the same confidentiality guidelines.