Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document the Security and Disclosure process for Agones #745

Closed
roberthbailey opened this issue Apr 25, 2019 · 6 comments
Closed

Document the Security and Disclosure process for Agones #745

roberthbailey opened this issue Apr 25, 2019 · 6 comments
Assignees
Labels
kind/feature New features for Agones
Milestone

Comments

@roberthbailey
Copy link
Member

We should document how to file security disclosures. @thisisnotapril mentioned that there was a brief mention somewhere but I didn't see anything on the agones.dev site in a quick search.

Strawman: Copy https://kubernetes.io/docs/reference/issues-security/security/ or https://istio.io/about/security-vulnerabilities/ and set up a mailing list to a limited distribution. The distribution should probably initially be the TSC unless folks are interested in handling security issues who are not part of the TSC.

/cc @markmandel

@roberthbailey roberthbailey added the kind/feature New features for Agones label Apr 25, 2019
@roberthbailey
Copy link
Member Author

@thisisnotapril - This seems like low hanging fruit to finish before we cut 1.0. Thoughts?

@roberthbailey
Copy link
Member Author

Right now if you file a bug, it mentions that if it's a security issue it should be disclosed privately but doesn't say where to report it:

If the matter is security related, please disclose it privately via

From https://raw.githubusercontent.com/googleforgames/agones/master/.github/ISSUE_TEMPLATE/bug_report.md

@roberthbailey
Copy link
Member Author

ping...

@roberthbailey
Copy link
Member Author

/assign @thisisnotapril

@roberthbailey
Copy link
Member Author

Bump.

@roberthbailey
Copy link
Member Author

I just found this old issue, and realized it was done in #2044.

@roberthbailey roberthbailey added this to the 1.14.0 milestone Oct 2, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/feature New features for Agones
Projects
None yet
Development

No branches or pull requests

2 participants