doc/security_issue_runbook.md
This runbook provides step-by-step guidance on handling a security advisory. Typically, it begins with a draft security advisory when we initiate the process outlined in this runbook. The draft security advisory is created by a contributor or a maintainer.
For information on what types of issues are considered security vulnerabilities and require a security advisory for resolution, please refer to identifying a security issue.
> A template for the advanced disclosure email
The Wamr project would like to announce a forthcoming security release.
The release will be made available on approximately YYYY-MM-DD. Additionally, an advisory will be made available on the same date at https://github.com/advisories.
The highest severity issue fixed in this release is classified as XXX based on the CVSS classification scheme.
> A template for the security release email
[Updated YYYY-MM-DD] Security release available.
WAMR release version X.Y.Z is now available. The binary release can be found on GitHub at https://github.com/bytecodealliance/wasm-micro-runtime/releases/tag/WAMR-Y.Y.Z. This release addresses the following security issues rated XXX: https://the link of the advisory
We’ll be conducting a full review of our security practices to ensure ample notification is provided for future security releases.
By following these steps, you can effectively manage and resolve security issues for your open source project, ensuring timely communication and collaboration while maintaining the integrity and security of your software.