Mission
To provide the utmost secure operating environment to Fedora and EPEL users by:
- working with packagers to patch and update packages,
- identifying and helping to improve secure development practices,
- answering software security questions from the community.
Contact
If you need help or assistance with any issue, please feel free to contact the FST members at
- IRC:
- #fedora-security[?] - general security questions
- #fedora-security-team[?] - Security Team IRC channel for working vulnerabilities
- Mailing lists:
- security - General security mailing list (good for questions)
- security-team - Security Team mailing list
- Weekly meetings:
- Every Thursday at 14:00 UTC. -> Schedule and Agenda
Security Response
To report a vulnerability in software please follow the procedure outlined on the Security Bugs page.
To report a security concern within the Fedora Project please email security at fedoraproject dot org.
What we do
Fedora Security Team aims to ensure that users are protected from vulnerabilities that exist in Fedora packages. Vulnerabilities are reported to Fedora package maintainers via Bugzilla by Red Hat Product Security. These bugs are marked with keywords: SecurityTracking attribute in Bugzilla, for ex. => CVE-2013-0333 rubygem-activesupport: json to yaml parsing. The SecurityTracking keyword indicates that the bug could have security implications which need to be investigated.
We help package maintainers follow up with upstream developers to obtain a patch or a new release which fixes the issue. Once such patch or a new release is available, the package maintainer then builds a new version of the package and submits an update to the Fedora or EPEL repositories via Bodhi.
How to get involved
Joining the team
Joining the Fedora Security Team is an easy, three-step process:
- subscribe to the security-team mailing list
- join us on the #fedora-security-team[?] IRC channel
- read the work flow
Once you feel comfortable just jump in and start helping. If you have questions please ask on IRC or on the mailing list.
Also, please take a look at the proposed Security Team Apprenticeship program as this may help answer additional questions.
Pages in category "Security Team"
The following 8 pages are in this category, out of 8 total.