What/Why
What are you proposing?
TSC to help advise on 'Best Practice' for LTS-vendor patches inclusion into next software release.
As part of the 'List of Requirements for OpenSearch LTS Vendors', the following is included:
Security & CVE Remediation SLAs
- LTS Version Maintenance Window: Support all designated LTS releases for their full 18-month lifecycle.
- CVE Patch Velocity:
- Critical / High CVEs: Must be patched within 30 days of public disclosure.
- Medium CVEs: Must be patched within 60 days of public disclosure.
- Unpatched Vulnerabilities: No medium or higher unpatched security vulnerabilities may remain unaddressed for longer than 30 days.
- Major Bug Fixes: Fix major bugs identified by the OSSF within 60 days of notification.
What users have asked for this feature?
Preemptive request to establish a release best practice for vendors that have signed up to support the OpenSearch Software Foundation LTS Program
What problems are you trying to solve?
An LTS vendor creates a patch, per the 'Security & CVE Remediation SLAs' requirement and contributes it back to the project - discussion around what a best practice might be to get that patch into an upcoming release.
- Is there a precedence to discuss for these patches as part of the formally defined LTS Program
- Is there a need to define a process
- What group or TAG could this process be assigned to
- What would a reasonable timeframe be for patch to be considered for inclusion in next release (i.e., if a patch is contributed 2 days before target release date, it is probably not reasonable to expect it considered for that release)
- Who owns QA/testing for this patch (affected repo maintainers, LTS vendor, combination of both?)
What/Why
What are you proposing?
TSC to help advise on 'Best Practice' for LTS-vendor patches inclusion into next software release.
As part of the 'List of Requirements for OpenSearch LTS Vendors', the following is included:
Security & CVE Remediation SLAs
What users have asked for this feature?
Preemptive request to establish a release best practice for vendors that have signed up to support the OpenSearch Software Foundation LTS Program
What problems are you trying to solve?
An LTS vendor creates a patch, per the 'Security & CVE Remediation SLAs' requirement and contributes it back to the project - discussion around what a best practice might be to get that patch into an upcoming release.