Skip to content

Security process  #16

Closed
Closed
@jankapunkt

Description

@jankapunkt

As already mentioned in the old discussion this project is highly security relevant:

What you gonna do? Issue is also, that this is a security relevant product. If you have a not trustworthy contributor/maintainer which puts malicious code into the product, then alot of companies will be hackable. But on the other hand, we can have a critical community and make it necessary to have x approvals before the maintainers can actually merge into master. I would also agree that new maintainers need to disclose their identities and who their employers are, so that making them to be maintainers does not mean to make a malicious anonymous able to taint the code.

I agree a lot with this. How do we want to ensure a high security in this project at all stages?

Also: assuming there is funding, do we want to get an independent security audit for certain releases?

Metadata

Metadata

Assignees

No one assigned

    Labels

    discussion 🗨️Discussion about a particular topic.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions