Blame SECURITY.md

Packit Service a04d08
# Security Policy
Packit Service a04d08
Packit Service a04d08
The following documents the upstream cloud-init security policy.
Packit Service a04d08
Packit Service a04d08
## Reporting
Packit Service a04d08
Packit Service a04d08
If a user finds a security issue, they are requested to file a [private
Packit Service a04d08
security bug on Launchpad](https://bugs.launchpad.net/cloud-init/+filebug).
Packit Service a04d08
To ensure the information stays private, change the "This bug contains
Packit Service a04d08
information that is:" from "Public" to "Private Security" when filing.
Packit Service a04d08
Packit Service a04d08
After the bug is received, the issue is triaged within 2 working days of
Packit Service a04d08
being reported and a response is sent to the reporter.
Packit Service a04d08
Packit Service a04d08
## cloud-init-security
Packit Service a04d08
Packit Service a04d08
The cloud-init-security Launchpad team is a private, invite-only team used to
Packit Service a04d08
discuss and coordinate security issues with the project.
Packit Service a04d08
Packit Service a04d08
Any issues disclosed to the cloud-init-security mailing list are considered
Packit Service a04d08
embargoed and should only be discussed with other members of the
Packit Service a04d08
cloud-init-security mailing list before the coordinated release date, unless
Packit Service a04d08
specific exception is granted by the administrators of the mailing list. This
Packit Service a04d08
includes disclosure of any details related to the vulnerability or the
Packit Service a04d08
presence of a vulnerability itself. Violation of this policy may result in
Packit Service a04d08
removal from the list for the company or individual involved.
Packit Service a04d08
Packit Service a04d08
## Evaluation
Packit Service a04d08
Packit Service a04d08
If the reported bug is deemed a real security issue a CVE is assigned by
Packit Service a04d08
the Canonical Security Team as CVE Numbering Authority (CNA).
Packit Service a04d08
Packit Service a04d08
If it is deemed a regular, non-security, issue, the reporter will be asked to
Packit Service a04d08
follow typical bug reporting procedures.
Packit Service a04d08
Packit Service a04d08
In addition to the disclosure timeline, the core Canonical cloud-init team
Packit Service a04d08
will enlist the expertise of the Ubuntu Security team for guidance on
Packit Service a04d08
industry-standard disclosure practices as necessary.
Packit Service a04d08
Packit Service a04d08
If an issue specifically involves another distro or cloud vendor, additional
Packit Service a04d08
individuals will be informed of the issue to help in evaluation.
Packit Service a04d08
Packit Service a04d08
## Disclosure
Packit Service a04d08
Packit Service a04d08
Disclosure of security issues will be made with a public statement. Once the
Packit Service a04d08
determined time for disclosure has arrived the following will occur:
Packit Service a04d08
Packit Service a04d08
* A public bug is filed/made public with vulnerability details, CVE,
Packit Service a04d08
  mitigations and where to obtain the fix
Packit Service a04d08
* An email is sent to the [public cloud-init mailing list](https://lists.launchpad.net/cloud-init/)
Packit Service a04d08
Packit Service a04d08
The disclosure timeframe is coordinated with the reporter and members of the
Packit Service a04d08
cloud-init-security list. This depends on a number of factors:
Packit Service a04d08
Packit Service a04d08
* The reporter might have their own disclosure timeline (e.g. Google Project
Packit Service a04d08
  Zero and many others use a 90-days after initial report OR when a fix
Packit Service a04d08
  becomes public)
Packit Service a04d08
* It might take time to decide upon and develop an appropriate fix
Packit Service a04d08
* A distros might want extra time to backport any possible fixes before
Packit Service a04d08
  the fix becomes public
Packit Service a04d08
* A cloud may need additional time to prepare to help customers or impliment
Packit Service a04d08
  a fix
Packit Service a04d08
* The issue might be deemed low priority
Packit Service a04d08
* May wish to to align with an upcoming planned release