Skip to content

guide: document embargoed security releases - #4152

Merged
Ben Hillis (benhillis) merged 1 commit into
microsoft:mainfrom
benhillis:user/benhill/openvmm-security-embargo-policy
Aug 5, 2026
Merged

guide: document embargoed security releases#4152
Ben Hillis (benhillis) merged 1 commit into
microsoft:mainfrom
benhillis:user/benhill/openvmm-security-embargo-policy

Conversation

@benhillis

Copy link
Copy Markdown
Member

Summary

  • document private vulnerability reporting and MSRC-owned coordinated disclosure
  • define case-by-case advance sharing with qualified downstream security teams
  • describe simultaneous publication of the public fix, patch-version source release, advisory, and CVE
  • keep internal repository, build, deployment, and customer-operational details out of the public guide

Context

This is a draft policy for team and downstream consensus. It assumes the source-only, manually published standalone release model proposed in #4150; it does not add or change release implementation.

Questions for reviewers

  • Are the eligibility and handling rules for advance patch sharing sufficiently strict and clear?
  • Is the incident-specific hosted-service deployment exception appropriate?
  • Is the patch-version release and supported-version language the right public commitment?

Describe MSRC-coordinated private fix development, qualified downstream patch sharing, and coordinated patch-version source releases.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4fe65aa5-d620-4856-a525-e32bf98c16b1
Copilot AI review requested due to automatic review settings August 4, 2026 00:45
@github-actions github-actions Bot added the Guide label Aug 4, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds Guide documentation for handling embargoed security fixes and coordinated disclosure, clarifying how OpenVMM should accept private vulnerability reports and publish security releases while keeping internal operational details out of the public Guide.

Changes:

  • Add a new “Security Releases” contributor-guide page describing private reporting via MSRC, embargoed fix development, downstream coordination, and coordinated disclosure.
  • Add the new page to SUMMARY.md navigation under Contributing.
  • Cross-link from the existing release management page to the new security releases guidance.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

File Description
Guide/src/SUMMARY.md Adds the new “Security Releases” page to the Contributing section navigation.
Guide/src/dev_guide/contrib/security_releases.md New policy page documenting private vulnerability reporting, embargo handling, downstream coordination, and disclosure steps.
Guide/src/dev_guide/contrib/release.md Adds a “See also” admonish link pointing readers to the new security releases page.

Comment thread Guide/src/dev_guide/contrib/security_releases.md
@benhillis
Ben Hillis (benhillis) marked this pull request as ready for review August 5, 2026 17:51
@benhillis
Ben Hillis (benhillis) requested a review from a team as a code owner August 5, 2026 17:51
@benhillis
Ben Hillis (benhillis) merged commit 92cf1d1 into microsoft:main Aug 5, 2026
134 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants