Skip to content

Security: intel/intel-application-migration-tool-for-openacc-to-openmp

Security

SECURITY.md

<title>Security Vulnerability Handling &#8212; OpenEcosystem Portal</title>
<link rel="stylesheet" type="text/css" href="../_static/pygments.css" />
<link rel="stylesheet" type="text/css" href="../_static/css/blank.css" />
<link rel="stylesheet" type="text/css" href="../_static/bootstrap-icons/font/bootstrap-icons.css" />
<link rel="stylesheet" type="text/css" href="../_static/dlux-bootstrap/css/dlux.min.css" />
<link rel="stylesheet" type="text/css" href="../_static/OSPO/css/ospo.css" />
<link rel="stylesheet" type="text/css" href="../_static/star-rating.js/dist/star-rating.css" />
<script data-url_root="../" id="documentation_options" src="../_static/documentation_options.js"></script>
<script src="../_static/jquery.js"></script>
<script src="../_static/underscore.js"></script>
<script src="../_static/doctools.js"></script>
<script src="../_static/rss-parser/rss-parser.min.js"></script>
<script src="../_static/OSPO/js/ospo.js"></script>
<script src="../_static/OSPO/js/slider.js"></script>
<script src="../_static/star-rating.js/dist/star-rating.js"></script>
<script src="../_static/dayjs/dayjs.min.js"></script>
<link rel="index" title="Index" href="../genindex.html" />
<link rel="search" title="Search" href="../search.html" />
<link rel="next" title="CVE Management of 3rd Party Components" href="Cvesecuritymanagement.html" />
<link rel="prev" title="Review System" href="Reviewsystem.html" />

<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta name="docsearch:language" content="None">


<!-- Google Analytics -->


<!-- Google tag (gtag.js) -->
<script async src="https://www.googletagmanager.com/gtag/js?id=G-2N6KKNN0T3"></script>
<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}
  gtag('js', new Date());

  gtag('config', 'G-2N6KKNN0T3');
</script>
	<div class="navbar-row sticky-top">
        <div class="nav-item dropdown align-items-center d-flex">
            <button class="btn dropdown-toggle nav-item border-0 text-uppercase text-dark" type="button"
                data-bs-toggle="dropdown" data-toggle="dropdown">
                Learning
            </button>
            <ul class="dropdown-menu dropdown-menu-left border-0">
                
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Learning.html 
        
    ">Learning</a>
            
            
                <ul class="m-0">
                    
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/licensing/Licensingtraining.html 
        
    ">Licensing Training Classes</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Preparingtheproject.html 
        
    ">Preparing for an Open Source Project</a>
            
            
                <ul class="m-0">
                    
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Whatisopensource.html 
        
    ">What is Open Source Software?</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/community/code-of-conduct.html 
        
    ">Contributor Covenant Code of Conduct</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/licensing/Licensingtraining.html 
        
    ">Licensing Training Classes</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Settinguptheteam.html 
        
    ">Setting Up the Team</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Developingintheopen.html 
        
    ">Developing in the Open</a>
            
            
        
    
    
                </ul>
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Prelaunch.html 
        
    ">Pre-Launch Activities - Chronological</a>
            
            
                <ul class="m-0">
                    
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Strategicplanning.html 
        
    ">Strategic Planning</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Creatingopengovernance.html 
        
    ">Creating an Openly Governed Project Governance Model</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/licensing/Licensing.html 
        
    ">Licensing Basics and Training</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Opensourcelicensingreview.html 
        
    ">Open Source Software Licensing Review</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/projectmanagement/Projectmanagement.html 
        
    ">Project Management</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Advocacymarketing.html 
        
    ">Advocacy and Marketing</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Documentation.html 
        
    ">Documentation: Tips and Best Practices</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Webpresence.html 
        
    ">Web Presence</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Preparingaproject.html 
        
    ">Open Source Software Release Approval</a>
            
            
        
    
    
                </ul>
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Launch.html 
        
    ">Launching a Project</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Developmentandmaintenance.html 
        
    ">Development and Maintenance - Alphabetic</a>
            
            
                <ul class="m-0">
                    
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Cicd.html 
        
    ">CI/CD Continuous Integration and Deployment</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Documentation.html 
        
    ">Documentation: Tips and Best Practices</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Issuemanagement.html 
        
    ">Issue Management</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Releasestrategy.html 
        
    ">Release Strategy</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Reviewsystem.html 
        
    ">Review System</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            #
        
    ">Security Vulnerability Handling</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Cvesecuritymanagement.html 
        
    ">CVE Management of 3rd Party Components</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Supplychainsecurity.html 
        
    ">Supply Chain Security</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Testingstrategy.html 
        
    ">Testing Strategy</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Webpresence.html 
        
    ">Web Presence</a>
            
            
        
    
    
                </ul>
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Community.html 
        
    ">Working with the Community</a>
            
            
                <ul class="m-0">
                    
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Communicationchannels.html 
        
    ">Communication Channels</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Developeroutreach.html 
        
    ">Developer Outreach</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Developermeetups.html 
        
    ">Developer Meetups</a>
            
            
        
    
    
                </ul>
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../Learning/Exitingaproject.html 
        
    ">Exiting an Open Source Project</a>
            
            
        
    
    
                </ul>
            
        
    
    
            </ul>
        </div>
    
    
      
        
         
        
    
    
    
        <div class="nav-item dropdown align-items-center d-flex">
            <button class="btn dropdown-toggle nav-item border-0 text-uppercase text-dark" type="button"
                data-bs-toggle="dropdown" data-toggle="dropdown">
                The Open Source Approval Process
            </button>
            <ul class="dropdown-menu dropdown-menu-left border-0">
                
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../OverallApproval/OverallApproval.html 
        
    ">The Open Source Approval Process</a>
            
            
                <ul class="m-0">
                    
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../OverallApproval/security/security.html 
        
    ">Mandatory: Security Development Lifecycle</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../OverallApproval/os-pdt/OpenSourcePDT.html 
        
    ">Mandatory: Open Source PDT</a>
            
            
                <ul class="m-0">
                    
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../OverallApproval/os-pdt/approval-process.html 
        
    ">The OSPDT Approval Process</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../OverallApproval/os-pdt/pdt-approval-workflow.html 
        
    ">Open Source PDT Approval Workflow</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../OverallApproval/os-pdt/faq.html 
        
    ">OSPDT Frequently Asked Questions</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../OverallApproval/os-pdt/proj-repo-naming.html 
        
    ">Open Source Software and Repo Naming Guidelines</a>
            
            
        
    
    
                </ul>
            
        
    
    
                </ul>
            
        
    
    
            </ul>
        </div>
    
    
      
        
         
        
    
    
    
        <div class="nav-item dropdown align-items-center d-flex">
            <button class="btn dropdown-toggle nav-item border-0 text-uppercase text-dark" type="button"
                data-bs-toggle="dropdown" data-toggle="dropdown">
                External Collaboration Tools
            </button>
            <ul class="dropdown-menu dropdown-menu-right border-0">
                
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab.html 
        
    ">External Collaboration Tools</a>
            
            
                <ul class="m-0">
                    
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab/linux.intel.com.html 
        
    ">linux.intel.com email Accounts for Patches</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab/linux-ftp.html 
        
    ">linux-ftp Mirror Network</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab/sles-license-server.html 
        
    ">SLES License & Repo Server</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab/otcirc.html 
        
    ">OTCIRC Chat Services</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab/github-external.html 
        
    ">Github External Hosting</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab/jira.html 
        
    ">Jira Consulting & Hosting</a>
            
            
                <ul class="m-0">
                    
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab/opensourcejira.html 
        
    ">Open Source Instance Hosting</a>
            
            
        
    
    
                </ul>
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab/ssh-key-policy.html 
        
    ">SSH Keying Policy</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab/download.01.org.html 
        
    ">download.01.org CDN Services</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab/mailinglists.html 
        
    ">Mailing Lists</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab/readthedocs-hosting.html 
        
    ">Read the Docs Hosting Services</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../sphinx-bkms.html 
        
    ">Sphinx BKMs</a>
            
            
                <ul class="m-0">
                    
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../sphinx-bkms/index.html 
        
    ">Sphinx overview</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../sphinx-bkms/getting-started/index.html 
        
    ">Getting started</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../sphinx-bkms/writing-rst/index.html 
        
    ">reSTructuredText Syntax</a>
            
            
        
    
    
                </ul>
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../ExtCollab/opensourcejira.html 
        
    ">Open Source Instance Hosting</a>
            
            
        
    
    
                </ul>
            
        
    
    
            </ul>
        </div>
    
    
      
        
         
        
    
    
        
            <div class="nav-item d-flex align-items-center"  >
                <a 
                    class="nav-link text-uppercase text-dark" href="
    
        
            
            ../IntelOutside/IntelOutside.html 
        
    ">
                    Community and Evangelism
                </a>
            </div>
       
    
    
      
        
         
        
    
    
    
        <div class="nav-item dropdown align-items-center d-flex">
            <button class="btn dropdown-toggle nav-item border-0 text-uppercase text-dark" type="button"
                data-bs-toggle="dropdown" data-toggle="dropdown">
                Open Source Projects
            </button>
            <ul class="dropdown-menu dropdown-menu-right border-0">
                
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../2023OESummit/presentations.html 
        
    ">OpenEcoSummit Keynotes, Tech Sessions</a>
            
            
        
    
        
            
                <a 
                   class="dropdown-item"  href="
    
        
            
            ../2023OESummit/videoPortal.html 
        
    ">Open Source Project Videos</a>
            
            
        
    
    
            </ul>
        </div>
    
    
      
      
        
    
    
    
        <div class="nav-item dropdown align-items-center d-flex">
            <button class="btn dropdown-toggle nav-item border-0 text-uppercase text-dark" type="button"
                data-bs-toggle="dropdown" data-toggle="dropdown">
                Quick Links
            </button>
            <ul class="dropdown-menu dropdown-menu-right border-0">
                
    
        
            
                <a target="_blank" 
                   class="dropdown-item"  href="
    
        
            https://intel.sharepoint.com/sites/Trade/SitePages/What-is-Subject-to-Export-Control.aspx
        
    ">Export Control</a>
            
            
        
    
        
            
                <a target="_blank" 
                   class="dropdown-item"  href="
    
        
            https://intel.sharepoint.com/sites/SWLC
        
    ">Software Legal Compliance</a>
            
            
        
    
        
            
                <a target="_blank" 
                   class="dropdown-item"  href="
    
        
            https://legal.intel.com/Trademarks/
        
    ">Trademark and Brands</a>
            
            
        
    
        
            
                <a target="_blank" 
                   class="dropdown-item"  href="
    
        
            https://intel.sharepoint.com/sites/sdl?e=1%3Aa6a73cc602ce42c1ad6a63170447ad70
        
    ">SDL Essentials Portal</a>
            
            
        
    
        
            
                <a target="_blank" 
                   class="dropdown-item"  href="
    
        
            https://intel.sharepoint.com/sites/ospdt/Lists/OSPDT%20Meeting%20Calendar/calendar.aspx
        
    ">Open Source PDT Meeting Calender</a>
            
            
        
    
        
            <div class="dropdown-divider"></div>
        
    
        
            
                <a target="_blank" 
                   class="dropdown-item"  href="
    
        
            https://circuitplus.intel.com/channels/5606468
        
    ">Open Ecosystem Circuit+ Channel</a>
            
            
        
    
        
            
                <a target="_blank" 
                   class="dropdown-item"  href="
    
        
            https://open.intel.com
        
    ">Open Ecosystem - Public Website</a>
            
            
        
    
        
            
                <a target="_blank" 
                   class="dropdown-item" title="Featuring the projects and people who work to combine Intel's unique strengths in hardware with a commitment to a strong, open ecosystem." href="
    
        
            https://intel.sharepoint.com/sites/openinnovationseries
        
    ">Open Source Innovations Meetups</a>
            
            
        
    
        
            
                <a target="_blank" 
                   class="dropdown-item"  href="
    
        
            https://openatintel.podbean.com/
        
    ">Open@Intel Podcasts</a>
            
            
        
    
        
            <div class="dropdown-divider"></div>
        
    
        
            
                <a target="_blank" 
                   class="dropdown-item"  href="
    
        
            https://grit.intel.com/
        
    ">Intel Library - Tech, Mkting, Biz Journals</a>
            
            
        
    
    
            </ul>
        </div>
    
    
      
      <div class="nav-item">
          <form class="bd-search d-flex align-items-center mr-1" action="../search.html" method="get">
    
</ul>
	</div>

    
    






<div class="bd-container">
     
       
           <!-- Only show if we have sidebars configured, else just a small margin  -->
           <div class="bd-sidebar"><nav class="bd-links w-100" id="bd-docs-nav" aria-label="Main navigation">
  <main class="bd-main">
        

            <div class="content-row h-100" >

                <div class="bd-content">

                    <div class="bd-article-container">

                            




                    
                    
                        <div id="bodyRow" class="row" role="main">

Security Vulnerability Handling

Your Roles and Responsibilities

Where and how to handle a security issue in open source projects can be confusing. Please review the IPAS policy for open source security vulnerability handling and SDL Guidance for Open Source and Co-development to fully understand your role and responsibilities. A developer training to help you better understand your individual role is available here.

An internal mailing list - oss-security@eclists.intel.com - is available if you require assistance in either understanding your role and responsibilities, or how to handle a vulnerability within a specific project or product.

Intel-Owned Project/Product Responsibilities

If you are responsible for a public Intel-owned opensource project you must:

  • Provide a public security policy that directs users to report security issues to secure@intel.com.

    • Intel owned projects hosted on GitHub, especially any projects in official Intel GitHub organizations, should include a default security.md file that directs users into IPAS to report any security issues found in that project. Please download the default security.md and include it in the root of your github repository.

  • Report any security issues identified during development to secure@intel.com

  • You must work with  IPAS to disclose issues and mitigations to your users.

  • EXCEPTION: Intel staging should refer third-parties to the community project the staging tree feeds into.

If you consume opensource software in an Intel branded product you must:

  • Ensure that the project is well maintained and can fix and merge issues in a timely way into a regular release cadence.

  • Ensure that the project(s) has a security issue handling policy that defines:

    • How security issues will be reported to the project, and whether that method is private or public.

    • How issues will be disclosed to users, and on what timeline

  • Report any security issues in projects you consume in released versions of your product to secure@intel.com

  • NOTE: If you consume critical dependencies from poorly maintained projects without defined security processes, you may be required to either remove the dependency, or mitigate known security vulnerabilities directly within your project.

Community Project Expectations

Intel would like to see a minimal security vulnerability process in place for any upstream community project Intel creates or participates in. That process would ideally include:

  • A private channel for reporting security issues to the project

  • A defined timeline for public disclosure of the issue/patches starting from the initial report.

  • A defined security advisory publication and CVE process.

An internal mailing list - oss-security@eclists.intel.com - is available if you require assistance in either understanding your role and responsibilities, or how to handle a vulnerability within a specific project or product.


Revision History

v1.0 Initial Release June 2023
                        </div>
                    

                            




                    </div>

                  </div>

        		  
                  
               		 

                  
                    <div class="bd-sidebar-secondary bd-toc">
On this page
                    </div>
                  

                </div>
                  

        

  </main>
<script src="../_static/js/index.be7d3bbb2ef33a8344ce.js"></script>
<div class="footer-item">
<div class="col">
    <div class="card border-0 m-0 bg-tranparent">
       <div class="card-body p-0">
           <h4 class="card-title">Our Organization</h4>
                
                <a 
                    class="nav-link" href="

    
        https://intel.sharepoint.com/sites/strategytoexecution/SitePages/Open.Intel.aspx
    
">Open Ecosystem Org</a>
                
                <a 
                    class="nav-link" href="

    
        https://intel.sharepoint.com/sites/strategytoexecution
    
">Strategy to Execution (S2E)</a>
                
                <a 
                    class="nav-link" href="

    
        https://intel.sharepoint.com/sites/SATG
    
">Office of the CTO & SATG</a>
                
       </div>
   </div>
</div>

<div class="col">
    <div class="card border-0 m-0 bg-tranparent">
       <div class="card-body p-0">
           <h4 class="card-title">Contact Us</h4>
                
                <a 
                    class="nav-link" href="

    
        https://web.yammer.com/main/org/intel.com/groups/eyJfdHlwZSI6Ikdyb3VwIiwiaWQiOiIxMjczNzU0NDE5MiJ9/new
    
">Open Ecosystem or content queries</a>
                
                <a 
                    class="nav-link" href="

    
        mailto:stephen.e.ware@intel.com
    
">Broken links, failed pages...</a>
                
       </div>
   </div>
</div>


<div class="col">
    <div class="card border-0 m-0 bg-tranparent">
       <div class="card-body p-0">
           <h4 class="card-title">Rate this page</h4>
           <select id="starrating" class="star-rating" 
               onchange="(() => gtag('event', 'star_rating', { stars: document.getElementById('starrating').value}))()">
               <option value="5">Excellent</option>
               <option value="4">Very Good</option>
               <option value="3">Average</option>
               <option value="2">Poor</option>
               <option value="1">Terrible</option>
           </select>
       </div>
   </div>
</div>
<script> var stars = new StarRating('.star-rating', {tooltip:false}); </script>
</div>

There aren’t any published security advisories