Skip to content

Create a security policy.#126

Draft
wmaroneAMD wants to merge 1 commit intomainfrom
psirt-security-policy
Draft

Create a security policy.#126
wmaroneAMD wants to merge 1 commit intomainfrom
psirt-security-policy

Conversation

@wmaroneAMD
Copy link
Copy Markdown
Collaborator

This policy is derived from the Caliptra PSIRT policy found here:

https://github.com/chipsalliance/Caliptra/blob/main/SECURITY.md

Next is to tune this to fit OpenPRoT specifics.

@wmaroneAMD wmaroneAMD force-pushed the psirt-security-policy branch from 083f863 to 9783945 Compare March 4, 2026 23:15
@wmaroneAMD
Copy link
Copy Markdown
Collaborator Author

Open questions:

  • Will Github's mechanisms suffice for us, or do we need to employ ChipsAlliance's infrastructure (mailing list, etc.)
  • Set up our own CNA? I don't think our scope is big enough quite yet.

This policy is derived from the Caliptra PSIRT policy found here:

https://github.com/chipsalliance/Caliptra/blob/main/SECURITY.md

Next is to tune this to fit OpenPRoT specifics.
@wmaroneAMD wmaroneAMD force-pushed the psirt-security-policy branch from 9783945 to aa8c463 Compare March 4, 2026 23:25
@FerralCoder
Copy link
Copy Markdown
Collaborator

Open questions:

  • Will Github's mechanisms suffice for us, or do we need to employ ChipsAlliance's infrastructure (mailing list, etc.)
  • Set up our own CNA? I don't think our scope is big enough quite yet.

Given my experience with Caliptra, I feel that the overhead of setting up our own CNA is a step too far.

As for the question on mailing lists, etc... I am torn on that.

  • On the one hand, using a mailing list for submitting issues is common practice, while the GitHub Private Vulnerability Reporting mechanism is relatively new. Also, I am not sure how we would notify potentially affected parties during the embargo period without some sort of outbound list.
  • On the other hand, an inbound mailing list requires constant monitoring in addition to everything controlled through GitHub. Using the built-in mechanism means that everything is in one place and simpler to manage.

Opinions?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants