Skip to content

[PROPOSAL] LTS-vendor patch inclusion Best Practices #129

Description

@krisfreedain

What/Why

What are you proposing?

TSC to help advise on 'Best Practice' for LTS-vendor patches inclusion into next software release.

As part of the 'List of Requirements for OpenSearch LTS Vendors', the following is included:

Security & CVE Remediation SLAs

  • LTS Version Maintenance Window: Support all designated LTS releases for their full 18-month lifecycle.
  • CVE Patch Velocity:
    • Critical / High CVEs: Must be patched within 30 days of public disclosure.
    • Medium CVEs: Must be patched within 60 days of public disclosure.
    • Unpatched Vulnerabilities: No medium or higher unpatched security vulnerabilities may remain unaddressed for longer than 30 days.
  • Major Bug Fixes: Fix major bugs identified by the OSSF within 60 days of notification.

What users have asked for this feature?

Preemptive request to establish a release best practice for vendors that have signed up to support the OpenSearch Software Foundation LTS Program

What problems are you trying to solve?

An LTS vendor creates a patch, per the 'Security & CVE Remediation SLAs' requirement and contributes it back to the project - discussion around what a best practice might be to get that patch into an upcoming release.

  • Is there a precedence to discuss for these patches as part of the formally defined LTS Program
  • Is there a need to define a process
  • What group or TAG could this process be assigned to
  • What would a reasonable timeframe be for patch to be considered for inclusion in next release (i.e., if a patch is contributed 2 days before target release date, it is probably not reasonable to expect it considered for that release)
  • Who owns QA/testing for this patch (affected repo maintainers, LTS vendor, combination of both?)

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions