Security Severity Ratings/Merge: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
Line 169: Line 169:
! style="width:5%" | Examples
! style="width:5%" | Examples
|-
|-
|<b>sg-assigned:UserAlias</b>
|<b>sec-assigned:UserAlias</b>
|This designates the assigned security resource that is accountable for actions to be taken on the designated item. When possible the bug will be assigned to the security contact for action. This will be used when that is not possible or practical.
|This designates the assigned security resource that is accountable for actions to be taken on the designated item. When possible the bug will be assigned to the security contact for action. This will be used when that is not possible or practical.
|[sg-assigned:curtisk] indicates that curtisk is the accountable party for action
|[sg-assigned:curtisk] indicates that curtisk is the accountable party for action

Revision as of 15:55, 26 March 2012

Security bugs are rated by specifying "sec-<rating>" in the "Keyword" field in bugzilla. For example, a bug with a Critical security rating would be marked as "sec-critical".

Severity Ratings

Additional Security Status Codes

If a potential security issue has not yet been assigned a severity rating, or a rating is not appropriate, the whiteboard may instead contain one of the following security status codes.

Transition Plan

Example Searches

Archive

archive