Eclipse Foundation Security Training - How We Manage Vulnerability Reports
Eclipse Foundation via YouTube
Overview
Syllabus
00:00 Introduction & Format
00:48 Vulnerability Reporting at Eclipse Foundation
03:10 Process for Handling Reports GitLab & GitHub
06:05 Private Issue Management & Disclosure Best Practices
09:41 GitHub Private Advisories: Reporting & Visibility
11:02 Mailing Lists and Process Improvements
12:07 Handling End-of-Life Versions and Unsupported Releases
13:04 How the Security Team Supports Projects
14:05 Quiz & Live Questions
17:05 CVSS Scoring and Severity Determination
19:01 Business Impact vs. Technical Scores
22:17 Quiz Results & Recap
24:00 Resources, Badge Survey & Final Reminders
Taught by
Eclipse Foundation