Info |
---|
The processes defined are ONAP Vulnerability Management and the onap-security mail alias are only to report issues against the ONAPplatform itself, not the supporting infrastructure that is used by this opensource community.software itself. It is NOT to be used for any issues related to tools and infrastructure (DNS, email, web, etc.)
|
...
- The Linux Kernel process for reporting security issues
- The OpenDaylight vulnerability management process
- Recommendations for a minimal security response process
- The fd.io vulnerability management process
Vulnerability Management Process Overview
Vulnerability Management Process
...
A report can be received either as a ticket in Vulnerability Reporting Jira Project, email to onap-security@lists.onap.org or as a private encrypted email to one of the VMS members .
Steps that has to be completed depend on reception method:
...