Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The ASF Security team is a CVE Project Candidate Naming Authority (CNA). CVE names are issued to vulnerabilities regardless if they are found by the project committers, members, PMCs, other ASF members, or third-parties.  The ASF Security team and PMCs work from time to time with third parties who wish to perform security functions such as code audits , and bug bounties.  

The ASF Security team assist the PMC PMCs in publishing a CVE once the vulnerability has been patched and a release containing the patch has been made available.  Vulnerability reports are sent to common and consistent locations including security lists, project development lists, and announce@apache.org. The security team oversee oversees all reported issues across all ASF projects.  The security team report reports monthly to the board and produce produces other public reports:

...