Skip to content

Add SECURITY.md referencing EVE security policy - #23

Merged
milan-zededa merged 1 commit into
lf-edge:mainfrom
eriknordmark:security-md
Sep 9, 2026
Merged

milan-zededa merged 1 commit into
lf-edge:mainfrom
eriknordmark:security-md

Conversation

@eriknordmark

Copy link
Copy Markdown
Contributor

Description

eve-rust is part of the EVE project but carries no security policy of its own, so GitHub shows no reporting instructions on this repository and a researcher who finds an issue here has no private channel to use.

The added SECURITY.md names the private reporting channels the project already uses — eve-security@lists.lfedge.org and GitHub private vulnerability reporting on lf-edge/eve — and defers to the main EVE repository for supported versions, response timeline and the coordinated disclosure process. That keeps one authoritative policy for the project rather than a copy per repository that drifts.

The same file is going into the other EVE-family repositories that lack one, and the existing copies in edge-containers, eve-build-tools, rol and runx are being repointed in parallel PRs: they link to eve/blob/master/docs/SECURITY.md, which has returned 404 since that file was renamed to docs/SECURITY-ARCHITECTURE.md.

This repository is part of the EVE project but carries no security
policy of its own, so a researcher who lands here is offered no private
reporting channel and no sign that one exists. Name the private channels
the project already uses, and defer to the main EVE repository for
supported versions, response timeline and the coordinated disclosure
process, so the project keeps one authoritative policy rather than a
divergent copy per repository.

Signed-off-by: eriknordmark <erik@zededa.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@milan-zededa
milan-zededa merged commit fb6692a into lf-edge:main Sep 9, 2026
3 checks passed
@eriknordmark
eriknordmark deleted the security-md branch September 19, 2026 00:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants