Difference between revisions of "Security Teams"
(→Security SIG) |
(→Security SIG) |
||
| Line 4: | Line 4: | ||
==Security SIG == | ==Security SIG == | ||
| − | * [[Security SIG|Security SIG wiki page]] | + | * [[Security-SIG|Security SIG wiki page]] |
* Security experts and auditors working on OpenStack security | * Security experts and auditors working on OpenStack security | ||
* Publishes OSSN (OpenStack Security Notes) | * Publishes OSSN (OpenStack Security Notes) | ||
Latest revision as of 20:07, 14 April 2025
OpenStack historically had two security organizations - the Vulnerability Management Team (VMT) and the OpenStack Security Group (OSSG).
These organizations have now combined under the Security Project. The VMT continues to operate as a largely independent body for confidentially handling vulnerabilities but with stronger ties to the Security Project as a whole, which leads efforts to make OpenStack more secure through education, software tooling and security evangelism.
Security SIG
- Security SIG wiki page
- Security experts and auditors working on OpenStack security
- Publishes OSSN (OpenStack Security Notes)
- Advises on Vulnerability Metrics
Vulnerability Management team (VMT)
- https://launchpad.net/~openstack-vuln-mgmt
- Handles incoming vulnerability reports, following VulnerabilityManagement
- Publishes OSSA (OpenStack Security Advisories)