tree e2bfa9d058ab87844fd6b728ca3decbebb6e295a
parent 5b4f5d6b242391c43fe979b895a31c3820a967b2
author Joseph Reynolds <jrey@us.ibm.com> 1531775522 -0500
committer Gunnar Mills <gmills@us.ibm.com> 1540823128 +0000

Create security vulnerability reporting mechanism

This documents the process to privately report OpenBMC
security vulnerabilities with the intention of giving
time to the project to fix the problem before public
disclosure.

This first commit establishes the project's scope.
The next commit:
 - provides guidelines to the OpenBMC security response team as it
   works to address the security issues and disclose publicly
 - establishes the "How to report security vulnerabilities" web
   page to tell problem submitters what to include in their report
   and what to expect from the OpenBMC security response team

Change-Id: Ib90070f998a815ba3f4430c7eb6ff84b3934e012
Signed-off-by: Joseph Reynolds <jrey@us.ibm.com>
