Skip to content

[DOCS] Rename LLVM Security Group to LLVM Security Response Group. #116986

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Dec 18, 2024

Conversation

smithp35
Copy link
Collaborator

Rename LLVM Security Group to LLVM Security Response Group. Take the opportunity to canonicalise security group and Security Group to LLVM Security Response Group.

At the 2024-11-19 LLVM Security Group meeting [1] we discussed that in practice the LLVM Security Group was performing an incident response role, but it was not proactively adding additional testing, fuzzing and hardening. We do not want projects that use LLVM to see the LLVM Security Group as guaranteeing security for LLVM.

We decided that it would be useful to rename the group to LLVM Security Response Group as that reflects the work that it is doing.

There may be a case for a proactive security group with a different remit, but this is out of scope of this commit.

[1]
https://discourse.llvm.org/t/llvm-security-group-public-sync-ups/62735/32

Rename LLVM Security Group to LLVM Security Response Group. Take
the opportunity to canonicalise security group and Security Group
to LLVM Security Response Group.

At the 2024-11-19 LLVM Security Group meeting [1] we discussed that in
practice the LLVM Security Group was performing an incident response
role, but it was not proactively adding additional testing, fuzzing
and hardening. We do not want projects that use LLVM to see the
LLVM Security Group as guaranteeing security for LLVM.

We decided that it would be useful to rename the group to
LLVM Security Response Group as that reflects the work that it is
doing.

There may be a case for a proactive security group with a different
remit, but this is out of scope of this commit.

[1]
https://discourse.llvm.org/t/llvm-security-group-public-sync-ups/62735/32
@smithp35
Copy link
Collaborator Author

I've added all the security group members on the pick-list provided by Github.

There is a related PR #116980 for removing the one bullet point on the security group page that implies we do anything more than incident response.

We thought keeping the PRs separate was preferential as changing the LLVM Security Group name may need further consultation.

Copy link
Collaborator

@DimitryAndric DimitryAndric left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, wrong GitHub account :)

@smithp35 smithp35 merged commit ccb66bf into llvm:main Dec 18, 2024
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

8 participants