Re: [dpdk-dev] [PATCH] doc: prepare security process for vulnerabilities

2019-05-13 Thread Thomas Monjalon
07/05/2019 18:02, Thomas Monjalon: > In case a vulnerability is discovered, the process to follow > is described in this document. > It has been inspired by the process of some referenced projects > and with the help of experts from Intel, RedHat, Mellanox > and the Linux Foundation. > > Signed-of

Re: [dpdk-dev] [PATCH] doc: prepare security process for vulnerabilities

2019-05-08 Thread Thomas Monjalon
08/05/2019 00:38, Luca Boccassi: > On Tue, 2019-05-07 at 18:02 +0200, Thomas Monjalon wrote: > > create mode 100644 doc/guides/contributing/vulnerability.rst > > I think at least the fingerprint of the GPG key to encrypt to, if a > link to the whole public key given the page is served over https,

Re: [dpdk-dev] [PATCH] doc: prepare security process for vulnerabilities

2019-05-07 Thread Luca Boccassi
On Tue, 2019-05-07 at 18:02 +0200, Thomas Monjalon wrote: > In case a vulnerability is discovered, the process to follow > is described in this document. > It has been inspired by the process of some referenced projects > and with the help of experts from Intel, RedHat, Mellanox > and the Linux Fou

Re: [dpdk-dev] [PATCH] doc: prepare security process for vulnerabilities

2019-05-07 Thread Thomas Monjalon
07/05/2019 21:06, Stephen Hemminger: > Thomas Monjalon wrote: > > > In case a vulnerability is discovered, the process to follow > > is described in this document. [...] > Maybe there should be a keysigning at the DPDK summit Yes it is must for using GPG in the security process.

Re: [dpdk-dev] [PATCH] doc: prepare security process for vulnerabilities

2019-05-07 Thread Stephen Hemminger
On Tue, 7 May 2019 18:02:31 +0200 Thomas Monjalon wrote: > In case a vulnerability is discovered, the process to follow > is described in this document. > It has been inspired by the process of some referenced projects > and with the help of experts from Intel, RedHat, Mellanox > and the Linux F