mirror of
https://github.com/silverstripe/silverstripe-framework
synced 2024-10-22 14:05:37 +02:00
af7e055574
We're adopting CVSS (https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator), which allows us to classify the impact of security issues based on industry standard metrics. While there is still a lot of room for interpretation, it is more objective than our previous system of "critical/high/medium/low", with one sentence descriptions on how we interpret that "severity rating". This effectively changes our process to only apply security fixes to release lines in "limited support" (currently 3.6 and 3.7) if they're considered "critical" (CVSS > 9.0). We've already limited preannounces to CVSS >7.0 in these docs. |
||
---|---|---|
.. | ||
en | ||
_manifest_exclude | ||
LICENSE |