[Openstack-security] criteria for downstream stakeholders?

Ben Pfaff blp at nicira.com
Tue Feb 17 23:12:33 UTC 2015


Hi.  I'm a contributor to Open vSwitch.  Over in OVS, we're forming a
vulnerability management process, modeled on the one used in OpenStack
described at https://wiki.openstack.org/wiki/Vulnerability_Management.

We're trying to figure out what criteria to use for deciding what
companies or organizations qualify as downstream stakeholders.  Can
anyone tell us what criteria or policy OpenStack uses?

Thanks,

Ben.




More information about the Openstack-security mailing list