Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Info
The processes defined are

ONAP Vulnerability Management and the onap-security mail alias are only to report issues against the ONAP

platform itself, not the supporting infrastructure that is used by this opensource community.

software itself.  It is NOT to be used for any issues related to tools and infrastructure (DNS, email, web, etc.) 

  • If you would like to report a vulnerability against general project infrastructure (such as DNS, web or email services), please go to http://support.linuxfoundation.org/ → Project Services → Infrastructure Operations and file a bug.
  • The ONAP Project does not pay bug bounties.

...

Vulnerability Management Process Overview

Image Added

Vulnerability Management Process

...

A report can be received either as a ticket in Vulnerability Reporting Jira Project, email to onap-security@lists.onap.org or as a private encrypted email to one of the VMS members .

Steps that has to be completed depend on reception method:

...