This describes the OpenBMC security vulnerability reporting process which is intended to give the project time to address security problems before public disclosure.
The main pieces are:
The basic workflow is:
Note that the OpenBMC security response team is distinct from the OpenBMC security working group which remains completely open.
The How to privately report a security vulnerability web page explains how OpenBMC community members can report a security vulnerability and get a fix for it before public announcement of the vulnerability.
The openbmc-security@lists.ozlabs.org
email address is the primary communication vehicle between the person who reported the problem and the security response team, and the initial communication between the security response team members.
The Guidelines for security response team members contain collected wisdom for the response team and community members who are working to fix the problem.