Skip to content

Remove ich#8182

Open
nikhil-kalbande wants to merge 2 commits intoppc64le:masterfrom
nikhil-kalbande:remove_ich_id
Open

Remove ich#8182
nikhil-kalbande wants to merge 2 commits intoppc64le:masterfrom
nikhil-kalbande:remove_ich_id

Conversation

@nikhil-kalbande
Copy link
Copy Markdown
Contributor

@nikhil-kalbande nikhil-kalbande commented Apr 29, 2026

  • Removed reference of ICH email id as contact id for security issues
  • Added reference of OSE portal for checking CVE data

@janani66
Copy link
Copy Markdown

Suggested rewording of the whole doc:

Security Policy

Supported Versions

We provide build scripts for many (thousands) of open source projects, often covering multiple versions per project.

Failures related to the upstream projects or their source code should be assessed and reported directly to the corresponding open source community. We do not have the bandwidth to triage, track, or maintain context for issues that originate outside of our build scripts.

An Open Source Edge (OSE) portal is available at https://open-source-edge.developerfirst.ibm.com/. Please review the portal to identify version-specific SBOMs, licenses, and CVEs for a limited set of packages that are onboarded to the Manage Currency set.

If you identify a security issue introduced by our build process, please file an issue directly in this GitHub repository. If the vulnerability is publicly disclosed, ensure that the issue is reported against the specific build script directory where the issue exists.

Reporting a Vulnerability

If a vulnerability is reported via a GitHub issue, we will make a best-effort attempt to triage and assign it as quickly as possible. Given our agile development model, such issues are typically reviewed at the start of a two-week sprint. You should expect an initial response within approximately four weeks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants