From f00b07353957a9feae3bd634bf0c5236282d2083 Mon Sep 17 00:00:00 2001 From: "Christoph Bergmeister [MVP]" Date: Tue, 16 Jul 2019 21:27:42 +0100 Subject: [PATCH] Refactor security policy documentation so that they appear in the Security policy tab of GitHub (#9905) Co-Authored-By: Travis Plunk --- .github/CONTRIBUTING.md | 2 +- .github/ISSUE_TEMPLATE/Security_Issue_Report.md | 8 ++++---- .github/SECURITY.md | 5 +++++ docs/maintainers/issue-management.md | 5 ++--- 4 files changed, 12 insertions(+), 8 deletions(-) create mode 100644 .github/SECURITY.md diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index 075d5186e3..bf4cefe654 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -382,7 +382,7 @@ Once you sign a CLA, all your existing and future pull requests will have the st [testing-guidelines]: ../docs/testing-guidelines/testing-guidelines.md [running-tests-outside-of-ci]: ../docs/testing-guidelines/testing-guidelines.md#running-tests-outside-of-ci [issue-management]: ../docs/maintainers/issue-management.md -[vuln-reporting]: ../docs/maintainers/issue-management.md#Security-Vulnerabilities +[vuln-reporting]: ./SECURITY.md [governance]: ../docs/community/governance.md [using-prs]: https://help.github.com/articles/using-pull-requests/ [fork-a-repo]: https://help.github.com/articles/fork-a-repo/ diff --git a/.github/ISSUE_TEMPLATE/Security_Issue_Report.md b/.github/ISSUE_TEMPLATE/Security_Issue_Report.md index 410000d940..a0222650f6 100644 --- a/.github/ISSUE_TEMPLATE/Security_Issue_Report.md +++ b/.github/ISSUE_TEMPLATE/Security_Issue_Report.md @@ -9,12 +9,12 @@ assignees: 'TravisEz13' # Security Issue -Excerpt from [Issue Management - Security Vulnerabilities](https://github.com/PowerShell/PowerShell/blob/master/docs/maintainers/issue-management.md#security-vulnerabilities) +Excerpt from [Issue Management - Security Vulnerabilities](https://github.com/PowerShell/PowerShell/blob/master/.github/SECURITY.md) -> If you believe that there is a security vulnerability in PowerShell Core, +> If you believe that there is a security vulnerability in PowerShell, it **must** be reported to [secure@microsoft.com](https://technet.microsoft.com/security/ff852094.aspx) to allow for [Coordinated Vulnerability Disclosure](https://technet.microsoft.com/security/dn467923). **Only** file an issue, if secure@microsoft.com has confirmed filing an issue is appropriate. -When you have permission from secure@microsoft.com to file an issue here, -please use the Bug Report template and state in the description that you are reporting the issue in coordination with secure@microsoft.com. +When you have permission from [secure@microsoft.com](https://technet.microsoft.com/security/ff852094.aspx) to file an issue here, +please use the Bug Report template and state in the description that you are reporting the issue in coordination with [secure@microsoft.com](https://technet.microsoft.com/security/ff852094.aspx). diff --git a/.github/SECURITY.md b/.github/SECURITY.md new file mode 100644 index 0000000000..3277852a85 --- /dev/null +++ b/.github/SECURITY.md @@ -0,0 +1,5 @@ +# Security Vulnerabilities + +If you believe that there is a security vulnerability in PowerShell, +it **must** be reported to [secure@microsoft.com](https://technet.microsoft.com/security/ff852094.aspx) to allow for [Coordinated Vulnerability Disclosure](https://technet.microsoft.com/security/dn467923). +**Only** file an issue, if [secure@microsoft.com](https://www.microsoft.com/en-us/msrc/faqs-report-an-issue?rtc=1) has confirmed filing an issue is appropriate. diff --git a/docs/maintainers/issue-management.md b/docs/maintainers/issue-management.md index 1779a3a95b..4021d44c82 100644 --- a/docs/maintainers/issue-management.md +++ b/docs/maintainers/issue-management.md @@ -2,9 +2,8 @@ ## Security Vulnerabilities -If you believe that there is a security vulnerability in PowerShell Core, -it **must** be reported to [secure@microsoft.com](https://technet.microsoft.com/security/ff852094.aspx) to allow for [Coordinated Vulnerability Disclosure](https://technet.microsoft.com/security/dn467923). -**Only** file an issue, if [secure@microsoft.com](https://www.microsoft.com/en-us/msrc/faqs-report-an-issue?rtc=1) has confirmed filing an issue is appropriate. +If you believe that there is a security vulnerability in PowerShell, +first follow the [vulnerability issue reporting policy](../../.github/SECURITY.md) before submitting an issue. ## Long-living issue labels