Skip to content
Merged
Changes from 1 commit
Commits
Show all changes
24 commits
Select commit Hold shift + click to select a range
1461f86
docs: add document to handle security reports
UlisesGascon Mar 5, 2025
c30511c
docs: add Security Report Handling Flowchart
UlisesGascon Mar 5, 2025
1a9042a
docs: add roles
UlisesGascon Mar 7, 2025
7aac07b
docs: add runbook
UlisesGascon Mar 7, 2025
03d7b60
Update docs/handle_security_reports.md
UlisesGascon Mar 8, 2025
dba71a6
Update docs/handle_security_reports.md
UlisesGascon Mar 8, 2025
99b4102
Update docs/handle_security_reports.md
UlisesGascon Mar 8, 2025
054ab8a
fix: format issues
UlisesGascon Mar 8, 2025
707c04d
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
eec7b04
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
de83da8
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
e88d94d
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
ee83fa1
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
799e888
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
315b02c
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
183adc6
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
014a4b1
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
fbc2d2c
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
fa6bf1b
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
6bb6700
Update docs/handle_security_reports.md
UlisesGascon Apr 2, 2025
0241b7c
Update docs/handle_security_reports.md
UlisesGascon Apr 22, 2025
2544711
Update docs/handle_security_reports.md
UlisesGascon Apr 22, 2025
38b6532
Update docs/handle_security_reports.md
UlisesGascon Apr 22, 2025
8c09fbb
Update docs/handle_security_reports.md
UlisesGascon Apr 22, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
fix: format issues
  • Loading branch information
UlisesGascon authored Mar 8, 2025
commit 054ab8a04a129f45fed98000cc8e93db7d51b1ed
5 changes: 5 additions & 0 deletions docs/handle_security_reports.md
Original file line number Diff line number Diff line change
Expand Up @@ -150,13 +150,18 @@ Ideally, the report must contain **clear and detailed information** like (Affect
### Step 3: Patch and release

3.1 The security triage team will determine if this vulnerability will be patched and work on it. In case that the vulnerability won't be patched jump to step 4.

3.2 The mitigation team (remediation developer(s), analyst(s), reporter(s)) will work on the patch(es), re-evaluate the report once the patch is ready and include regression tests (when possible).

3.3 The Express TC will announce publicly (social media and public issues) that there is security path available and the plan to do a release with an specific date (ideally) and the versions affected without providing additional information to prevent early disclosure.

3.4 The security triage, along with the repo captain(s) and the TC team, will create the releases and publish them to npm. In some cases one vulnerability can affect multiple packages requiring several coordinated releases.


### Step 4: Public disclosure

4.1 At this stage the Security Report Coordinator (SRC) will make the advisory public and close the coordination issue (opened in step 1).

4.2 The Security Report Coordinator (SRC) will also help to publish a blog post about the vulnerability and the patch (if applicable, example [September 2024 Security Releases](https://expressjs.com/2024/09/29/security-releases.html)).

4.3 The TC team will do social media announcements about the vulnerability and the patch (if applicable, example [Tweet post](https://x.com/UseExpressJS/status/1772300472730198037)).