Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 4 additions & 3 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -172,7 +172,8 @@ patches, understand exact mitigation steps, etc.
should be reserved for remotely exploitable or privilege escalation issues. Otherwise, this
process can be skipped.
- The Fix Lead will email the patches to cncf-envoy-distributors-announce@lists.cncf.io so
distributors can prepare builds to be available to users on the day of the issue's announcement.
distributors can prepare builds to be available to users on the day of the issue's announcement. Any
patches against main will be updated and resent weekly.
Distributors should read about the [Private Distributors List](#private-distributors-list) to find
out the requirements for being added to this list.
- **What if a vendor breaks embargo?** The PST will assess the damage. The Fix Lead will make the
Expand Down Expand Up @@ -326,7 +327,7 @@ use of Envoy should:
have a way to privately stage and validate your updates that does not violate
the embargo.
7. Be willing to [contribute back](#contributing-back) as outlined above.
8. Be able to perform a security release of your product within a two week window from candidate fix
8. Be able to perform a security release of your product within a three week window from candidate fix
patch availability.
9. Have someone already on the list vouch for the person requesting membership
on behalf of your distribution.
Expand Down Expand Up @@ -406,7 +407,7 @@ We accept.

We are definitely willing to help!

> 8. Be able to perform a security release of your product within a two week window from candidate fix
> 8. Be able to perform a security release of your product within a three week window from candidate fix
patch availability.

We affirm we can spin out new security releases within a 2 week window.
Expand Down