Bug 8744 - Need to standardize on a format for security bugs
Summary: Need to standardize on a format for security bugs
Status: RESOLVED OBSOLETE
Alias: None
Product: Bugzilla
Classification: Infrastructure
Component: bugzilla (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium normal
Target Milestone: Q4
Assignee: Unassigned
QA Contact:
URL:
Whiteboard: NEWCOMER
Depends on:
Blocks:
 
Reported: 2015-12-01 15:04 UTC by Armin Kuster
Modified: 2025-02-06 16:18 UTC (History)
6 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: Don't know


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Armin Kuster 2015-12-01 15:04:26 UTC
We should have some format and or mechanism to identify bugs that are security in nature.

example:
Summary
libxml: CVE-2015-xxxxx

or have a flag to denote this issue is security related. We use 'security' in a keyword field.
Comment 1 Ross Burton 2015-12-01 15:15:00 UTC
Put the CVE-XXX-XXXX in the whiteboard, and then search for bugs with CVE- in the whiteboard?
Comment 2 Stephen K Jolley 2018-01-25 15:52:04 UTC
Need a review of Security items in Triage meeting.
Comment 3 Randy MacLeod 2025-02-06 16:18:45 UTC
See https://wiki.yoctoproject.org/wiki/Security