Skip to content

Add SECURITY.md referencing EVE security policy - #271

Merged
eriknordmark merged 1 commit into
lf-edge:eve-kernel-amd64-v6.12.49-genericfrom
eriknordmark:security-md
Sep 10, 2026
Merged

Add SECURITY.md referencing EVE security policy#271
eriknordmark merged 1 commit into
lf-edge:eve-kernel-amd64-v6.12.49-genericfrom
eriknordmark:security-md

Conversation

@eriknordmark

Copy link
Copy Markdown
Contributor

Description

eve-kernel is part of the EVE project but carries no security policy of its own, so GitHub shows no reporting instructions on this repository and a researcher who finds an issue here has no private channel to use.

The added SECURITY.md names the private reporting channels the project already uses — eve-security@lists.lfedge.org and GitHub private vulnerability reporting on lf-edge/eve — and defers to the main EVE repository for supported versions, response timeline and the coordinated disclosure process. That keeps one authoritative policy for the project rather than a copy per repository that drifts.

The same file is going into the other EVE-family repositories that lack one, and the existing copies in edge-containers, eve-build-tools, rol and runx are being repointed in parallel PRs: they link to eve/blob/master/docs/SECURITY.md, which has returned 404 since that file was renamed to docs/SECURITY-ARCHITECTURE.md.

One caveat specific to this repository: GitHub only surfaces SECURITY.md from the default branch, and the default branch here tracks a particular kernel version (eve-kernel-amd64-v6.12.49-generic at the time of writing). The file will need to be carried onto each new kernel branch that becomes the default, or the policy silently disappears from the repository's Security tab.

This repository is part of the EVE project but carries no security
policy of its own, so a researcher who lands here is offered no private
reporting channel and no sign that one exists. Name the private channels
the project already uses, and defer to the main EVE repository for
supported versions, response timeline and the coordinated disclosure
process, so the project keeps one authoritative policy rather than a
divergent copy per repository.

Signed-off-by: eriknordmark <erik@zededa.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@eriknordmark
eriknordmark requested review from rene and shjala September 9, 2026 13:44
@eriknordmark
eriknordmark merged commit 1e8f65d into lf-edge:eve-kernel-amd64-v6.12.49-generic Sep 10, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant