|
4 | 4 |
|
5 | 5 | The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
|
6 | 6 |
|
7 |
| -The Vulnerability Disclosure Working group is officially a [Graduated-level](https://github.com/ossf/tac/blob/main/process/working-group-lifecycle.md) working group within the OpenSSF <img align="right" src="https://github.com/ossf/tac/blob/main/files/images/OpenSSF_StagesBadges_graduated.png" width="100" height="100">> |
| 7 | +The Vulnerability Disclosure Working group is officially a [Graduated-level](https://github.com/ossf/tac/blob/main/process/working-group-lifecycle.md) working group within the OpenSSF <img alt="openssf gradtuated WG" align="right" src="https://github.com/ossf/tac/blob/main/files/images/OpenSSF_StagesBadges_graduated.png" width="100" height="100"><!-- markdownlint-disable-line MD033 --> |
8 | 8 |
|
9 |
| -<img align="right" src="https://github.com/ossf/wg-vulnerability-disclosures/blob/main/ossf-goose-vuln.png" width="300" height="300"><!-- markdownlint-disable-line MD033 --> |
| 9 | +<img alt="OpenSSF Vulnerability Disclosures Working Group logo" align="right" src="https://github.com/ossf/wg-vulnerability-disclosures/blob/main/ossf-goose-vuln.png" width="300" height="300"><!-- markdownlint-disable-line MD033 --> |
10 | 10 |
|
11 | 11 | ## **Mission**
|
| 12 | + |
12 | 13 | The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping develop and advocate well-managed vulnerability reporting and communication. We serve open source maintainers and developers, assist security researchers, and help downstream open source software consumers.
|
13 | 14 |
|
14 | 15 | ## **Vision**
|
| 16 | + |
15 | 17 | A world where coordinated vulnerability disclosure is a normal, easy, and expected process that is supported by guidance, automation, and tooling for maintainers, consumers, researchers, and vendors, with the goal of making open source software and the open source software supply chain more secure for everyone.
|
16 | 18 |
|
17 | 19 | A world where coordinated vulnerability disclosure is:
|
18 |
| -- a common, easy, and expected process |
| 20 | + |
| 21 | +- a common, easy, and expected process |
19 | 22 | - supported by well-documented guidance, automation, and tooling for open source maintainers and consumers, security researchers, and vendors
|
20 | 23 | - with the goal of making open source software and supply chains more secure for everyone.
|
21 | 24 |
|
@@ -43,7 +46,7 @@ We plan on addressing this challenge through the following actions:
|
43 | 46 |
|
44 | 47 | ## **Current work**
|
45 | 48 |
|
46 |
| -<img align="right" src="https://github.com/ossf/wg-vulnerability-disclosures/blob/main/ossf-vuln-wg.png" width="400" height="400"><!-- markdownlint-disable-line MD033 --> |
| 49 | +<img alt="diagram of current work" align="right" src="https://github.com/ossf/wg-vulnerability-disclosures/blob/main/ossf-vuln-wg.png" width="400" height="400"><!-- markdownlint-disable-line MD033 --> |
47 | 50 |
|
48 | 51 | - [Guides to coordinated vulnerability disclosure for open source software projects](https://github.com/ossf/oss-vulnerability-guide) to assist projects in handling vulnerabilities.
|
49 | 52 | - [Open Source Vulnerability Schema](https://github.com/ossf/osv-schema) - see also [osv.dev](https://osv.dev).
|
|
0 commit comments