<h2 id="itm1">Submit a CVE Issue</h2>
openEuler's security system scans CVE issues and submits CVE issues to the security committee of openEuler community. The issue title of a CVE issue must start with a CVE ID, followed by a brief description of the CVE issue, for example,
<h2 id="itm2">Security Group Distributes CVE Issues</h2>
The security Group will distribute the CVE issues to the related repos. CVE issues contain the following information:
+ [ASSIGNINGCNA]: assign the name of CNA
<h2 id="itm3">Handle CVE Issues</h2>
Maintainer identifies and distributes CVE issues. Solutions to CVE problems can be provided by contributors and submitted for review by the Maintainer or Committer. When submitting, please associate with CVE ISSUE and provide complete information in Issues:
+ [ASSIGNINGCNA]: assign the name of CNA
<h2 id="itm4">CVE Issues Management Policy</h2>
+ **Fast Way**: The openEuler rating is a serious security issue. The openEuler security team will start the fast track to provide solutions to the LTS versions involved and within the life cycle.
+ Security issues that have not flown into the official version: handled as a development version of ISSUE and incorporated into the current development version. Such issues do not require a security announcement;
<h2 id="itm5">CVE Issues Proceure</h2>
<img src="./security/procedure.png" width="100%" style="max-width:1079px" />
### 参考
[community]( 项目将用于管理社区运作、贡献等社区相关流程、工具使用介绍,请关注了解更多详情。
[Community]( 项目将用于管理社区运作、贡献等社区相关流程、工具使用介绍,请关注了解更多详情。
<h2 id="itm1">扫描和提交CVE问题</h2>
openEuler的安全系统会扫描属于openEuler软件包范围内的CVE问题,并向openEuler社区的安全团队提交CVE问题。CVE类的问题的issue标题必须以CVE ID起始,后面跟上CVE问题的简要描述,如:
**CVE-2019-11255:** CSI volume snapshot, cloning and resizing features can result in unauthorized volume data access or mutation
<h2 id="itm2">安全团队处理和分发CVE问题</h2>
安全团队会根据CVE问题所属的包分发对应的CVE ISSUE到repo内。CVE ISSUE会包含以下信息:
<h2 id="itm3">处理CVE问题</h2>
Maintainer会对CVE问题进行确认和分发。CVE问题的解决方案可以由贡献者提供,并经过Maintainer或Committer的评审提交。提交时请关联CVE ISSUE,并在ISSUE内提供完善的的信息:
<h2 id="itm4">CVE问题合入策略</h2>
+ **快速通道**:对openEuler评定级别是严重的安全类问题,openEuler安全团队会启动快速通道,优先向涉及到且在生命周期内的LTS版本提供解决方案。
+ 未流入正式版本的安全类问题:作为开发版本的ISSUE处理,合入到当前开发版本,此类问题也不需要发布安全公告;
<h2 id="itm5">CVE问题处理流程</h2>
<img src="./security/procedure.png" width="100%" style="max-width:1079px" />
<div class="col-md-12"> SIGs是社区根据领域划分的各个领域的兴趣小组,每一个小组会根据情况维护社区一个或者多个项目。</div>
