Skip to content

[DOCS] Remove bullet point on improving security over time. #116980

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Dec 18, 2024

Conversation

smithp35
Copy link
Collaborator

Remove the 6th bullet point "Strive to improve security over time, for example by adding additional testing, fuzzing and hardening after fixing issues."

At the security group meeting on 2024-11-19 we discussed the role the security group was performing in practice. We are in effect acting as a security response group, dealing with issues raised via the process given in the LLVM Security group page. We are not proactively adding additional testing fuzzing and hardening. While this could be considered an aspirational goal, it may give the implication that the LLVM Security Group is handling or at worst guaranteeing security for the LLVM project when in practice it is not.

Meeting notes:
https://discourse.llvm.org/t/llvm-security-group-public-sync-ups/62735/32

Remove the 6th bullet point "Strive to improve security over time, for
example by adding additional testing, fuzzing and hardening after
fixing issues."

At the security group meeting on 2024-11-19 we discussed the role the
security group was performing in practice. We are in effect acting as
a security response group, dealing with issues raised via the process
given in the LLVM Security group page. We are not proactively adding
additional testing fuzzing and hardening. While this could be
considered an aspirational goal, it may give the implication that the
LLVM Security Group is handling or at worst guaranteeing security for
the LLVM project when in practice it is not.

Meeting notes:
https://discourse.llvm.org/t/llvm-security-group-public-sync-ups/62735/32
@smithp35
Copy link
Collaborator Author

I've added all the security group members on the pick-list provided by Github.

Copy link
Member

@gburgessiv gburgessiv left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for this!

@smithp35 smithp35 merged commit 0e324b3 into llvm:main Dec 18, 2024
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants