Skip to content

Commit

Permalink
chore(migration):[TRI-797] Update NOTICE and SECURITY files for Eclipse
Browse files Browse the repository at this point in the history
  • Loading branch information
ds-jkreutzfeld committed Nov 10, 2022
1 parent 7a9deac commit e0937c9
Show file tree
Hide file tree
Showing 2 changed files with 14 additions and 66 deletions.
12 changes: 8 additions & 4 deletions NOTICE.md
Original file line number Diff line number Diff line change
@@ -1,11 +1,15 @@
# Notices

This content is part of [CatenaX](https://catena-x.net).
This content is produced and maintained by the Eclipse Tractus-X project.

* Project home: https://github.com/catenax-ng
* Project home: https://projects.eclipse.org/projects/automotive.tractusx

See the AUTHORS file(s) distributed with this work for additional information regarding authorship.

## Trademarks

Eclipse Tractus-X is a trademark of the Eclipse Foundation.

## Copyright

All content is the property of the respective authors or their employers. For
Expand All @@ -23,9 +27,9 @@ SPDX-License-Identifier: Apache-2.0
## Source Code

The project maintains the following source code repositories
in the GitHub organization https://github.com/catenax-ng:
in the GitHub organization https://github.com/eclipse-tractusx:

* https://github.com/catenax-ng/tx-item-relationship-service
* https://github.com/eclipse-tractusx/item-relationship-service


## Third-party Content
Expand Down
68 changes: 6 additions & 62 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,63 +1,7 @@
# Security Policy




## Reporting a bug in Catena-X




Report security bugs in Catena-X to "[email protected]".

Your report will be acknowledged within 5 days, and you’ll receive a more detailed response to your report within 10 days indicating the next steps in handling your submission.

After the initial reply to your report, the security team will endeavor to keep you informed of the progress being made towards a fix and full announcement, and may ask for additional information or guidance surrounding the reported issue.

Please do not report security bugs through public GitHub issues.




Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue:

- Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)

- Full paths of source file(s) related to the manifestation of the issue

- The location of the affected source code (tag/branch/commit or direct URL)

- Any special configuration required to reproduce the issue

- Step-by-step instructions to reproduce the issue

- Proof-of-concept or exploit code (if possible)

- Impact of the issue, including how an attacker might exploit the issue

This information will help us triage your report more quickly.




## Reporting a bug in a third party module

Security bugs in third party modules should be reported to their respective maintainers.




## Disclosure policy

Here is the security disclosure policy for Catena-X.

- The security report is received and is assigned a primary handler.

- This person will coordinate the fix and release process.

- Fixes are prepared for all releases which are still under maintenance.

- A suggested embargo date for this vulnerability is chosen. Typically the embargo date will be set to 72 hours. However, this may vary depending on the severity of the bug or difficulty in applying a fix.

This process can take some time, especially when coordination is required with maintainers of other projects.
Every effort will be made to handle the bug in as timely a manner as possible; however, it’s important that we follow the release process above to ensure that the disclosure is handled in a consistent manner.


## Reporting a Vulnerability

Please report a found vulnerability here:
[https://www.eclipse.org/security/](https://www.eclipse.org/security/)

0 comments on commit e0937c9

Please sign in to comment.