Bug 8744

Summary: Need to standardize on a format for security bugs
Product: [Infrastructure] Bugzilla Reporter: Armin Kuster <akuster>
Component: bugzillaAssignee: Unassigned <unassigned>
Status: RESOLVED OBSOLETE QA Contact:
Severity: normal    
Priority: Medium CC: akuster, infras.bug.watcher, Infras.watcher, randy.macleod, richard.purdie, ross.burton
Version: unspecified   
Target Milestone: Q4   
Hardware: x86   
OS: Multiple   
Whiteboard: NEWCOMER
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Don't know

Description Armin Kuster 2015-12-01 15:04:26 UTC
We should have some format and or mechanism to identify bugs that are security in nature.

example:
Summary
libxml: CVE-2015-xxxxx

or have a flag to denote this issue is security related. We use 'security' in a keyword field.
Comment 1 Ross Burton 2015-12-01 15:15:00 UTC
Put the CVE-XXX-XXXX in the whiteboard, and then search for bugs with CVE- in the whiteboard?
Comment 2 Stephen K Jolley 2018-01-25 15:52:04 UTC
Need a review of Security items in Triage meeting.
Comment 3 Randy MacLeod 2025-02-06 16:18:45 UTC
See https://wiki.yoctoproject.org/wiki/Security