cfallin commented on issue #20:
On initial read, this looks really good and is quite complete!
Only thing I would add is that, if the vulnerability is in a Rust crate used by others, adding an entry to the rustsec database is a good last step, after the CVE exists and is public. An example PR is here for last year's Cranelift CVE.
bnjbvr commented on issue #20:
(Forgot to say, sorry!) Great write-up, this definitely will streamline and structure the incident handling process!
pchickey commented on issue #20:
@cfallin Thanks, added a RustSec database step to the final section. We haven't been consistent in publishing to that database, but there is no reason not to be.
pchickey commented on issue #20:
Motion to finalize with a disposition to merge
This RFC was forgotten for a little while with one piece of unresolved feedback, which has now been resolved. We have been using it de-facto during the time it was open.
Stakeholders sign-off
This effects all Bytecode Alliance projects so I've copied the biggest stakeholder list I could find (#14) and added some new folks. I apologize if I missed anyone, I am happy to add folks.
Arm
- [ ] @akirilov-arm
- [ ] @sparker-arm
DFINITY
- [ ] @granstrom
Embark Studios
- [ ] @bnjbvr
- [ ] @repi
Fastly
- [ ] @cfallin
- [ ] @sunfishcode
- [ ] @fitzgen
- [x] @pchickey
- [ ] @peterhuene
- [ ] @acfoltzer
- [ ] @iximeow
- [ ] @aturon
- [ ] @cratelyn
- [ ] @elliottt
- [ ] @jameysharp
Google/Envoy
- [ ] @PiotrSikora
Intel
- [ ] @mingqiusun
- [ ] @abrown
- [ ] @jlb6740
Microsoft
- [ ] @squillace
Fermyon
- [ ] @bacongobbler
- [ ] @radu-matei
Mozilla
- [ ] @julian-seward1
- [ ] @yurydelendik
IBM
- [ ] @uweigand
wasmCloud
- [ ] @autodidaddict
Unaffiliated
- [ ] @tschneidereit
- [ ] @bjorn3
fitzgen edited a comment on issue #20:
Motion to finalize with a disposition to merge
This RFC was forgotten for a little while with one piece of unresolved feedback, which has now been resolved. We have been using it de-facto during the time it was open.
Stakeholders sign-off
This effects all Bytecode Alliance projects so I've copied the biggest stakeholder list I could find (#14) and added some new folks. I apologize if I missed anyone, I am happy to add folks.
Arm
- [ ] @akirilov-arm
- [ ] @sparker-arm
DFINITY
- [ ] @granstrom
Embark Studios
- [ ] @bnjbvr
- [ ] @repi
Fastly
- [ ] @cfallin
- [ ] @sunfishcode
- [x] @fitzgen
- [x] @pchickey
- [ ] @peterhuene
- [ ] @acfoltzer
- [ ] @iximeow
- [ ] @aturon
- [ ] @cratelyn
- [ ] @elliottt
- [ ] @jameysharp
Google/Envoy
- [ ] @PiotrSikora
Intel
- [ ] @mingqiusun
- [ ] @abrown
- [ ] @jlb6740
Microsoft
- [ ] @squillace
Fermyon
- [ ] @bacongobbler
- [ ] @radu-matei
Mozilla
- [ ] @julian-seward1
- [ ] @yurydelendik
IBM
- [ ] @uweigand
wasmCloud
- [ ] @autodidaddict
Unaffiliated
- [ ] @tschneidereit
- [ ] @bjorn3
cfallin edited a comment on issue #20:
Motion to finalize with a disposition to merge
This RFC was forgotten for a little while with one piece of unresolved feedback, which has now been resolved. We have been using it de-facto during the time it was open.
Stakeholders sign-off
This effects all Bytecode Alliance projects so I've copied the biggest stakeholder list I could find (#14) and added some new folks. I apologize if I missed anyone, I am happy to add folks.
Arm
- [ ] @akirilov-arm
- [ ] @sparker-arm
DFINITY
- [ ] @granstrom
Embark Studios
- [ ] @bnjbvr
- [ ] @repi
Fastly
- [x] @cfallin
- [ ] @sunfishcode
- [x] @fitzgen
- [x] @pchickey
- [ ] @peterhuene
- [ ] @acfoltzer
- [ ] @iximeow
- [ ] @aturon
- [ ] @cratelyn
- [ ] @elliottt
- [ ] @jameysharp
Google/Envoy
- [ ] @PiotrSikora
Intel
- [ ] @mingqiusun
- [ ] @abrown
- [ ] @jlb6740
Microsoft
- [ ] @squillace
Fermyon
- [ ] @bacongobbler
- [ ] @radu-matei
Mozilla
- [ ] @julian-seward1
- [ ] @yurydelendik
IBM
- [ ] @uweigand
wasmCloud
- [ ] @autodidaddict
Unaffiliated
- [ ] @tschneidereit
- [ ] @bjorn3
fitzgen edited a comment on issue #20:
Motion to finalize with a disposition to merge
This RFC was forgotten for a little while with one piece of unresolved feedback, which has now been resolved. We have been using it de-facto during the time it was open.
Stakeholders sign-off
This effects all Bytecode Alliance projects so I've copied the biggest stakeholder list I could find (#14) and added some new folks. I apologize if I missed anyone, I am happy to add folks.
Arm
- [ ] @akirilov-arm
- [ ] @sparker-arm
DFINITY
- [ ] @granstrom
Embark Studios
- [ ] @bnjbvr
- [ ] @repi
Fastly
- [x] @cfallin
- [ ] @sunfishcode
- [x] @fitzgen
- [x] @pchickey
- [ ] @peterhuene
- [ ] @acfoltzer
- [ ] @iximeow
- [ ] @aturon
- [ ] @cratelyn
- [ ] @elliottt
- [ ] @jameysharp
Google/Envoy
- [ ] @PiotrSikora
Intel
- [ ] @mingqiusun
- [ ] @abrown
- [ ] @jlb6740
Microsoft
- [x] @squillace
Fermyon
- [ ] @bacongobbler
- [ ] @radu-matei
Mozilla
- [ ] @julian-seward1
- [ ] @yurydelendik
IBM
- [ ] @uweigand
wasmCloud
- [ ] @autodidaddict
Unaffiliated
- [ ] @tschneidereit
- [ ] @bjorn3
jameysharp edited a comment on issue #20:
Motion to finalize with a disposition to merge
This RFC was forgotten for a little while with one piece of unresolved feedback, which has now been resolved. We have been using it de-facto during the time it was open.
Stakeholders sign-off
This effects all Bytecode Alliance projects so I've copied the biggest stakeholder list I could find (#14) and added some new folks. I apologize if I missed anyone, I am happy to add folks.
Arm
- [ ] @akirilov-arm
- [ ] @sparker-arm
DFINITY
- [ ] @granstrom
Embark Studios
- [ ] @bnjbvr
- [ ] @repi
Fastly
- [x] @cfallin
- [ ] @sunfishcode
- [x] @fitzgen
- [x] @pchickey
- [ ] @peterhuene
- [ ] @acfoltzer
- [ ] @iximeow
- [ ] @aturon
- [ ] @cratelyn
- [ ] @elliottt
- [x] @jameysharp
Google/Envoy
- [ ] @PiotrSikora
Intel
- [ ] @mingqiusun
- [ ] @abrown
- [ ] @jlb6740
Microsoft
- [x] @squillace
Fermyon
- [ ] @bacongobbler
- [ ] @radu-matei
Mozilla
- [ ] @julian-seward1
- [ ] @yurydelendik
IBM
- [ ] @uweigand
wasmCloud
- [ ] @autodidaddict
Unaffiliated
- [ ] @tschneidereit
- [ ] @bjorn3
pchickey edited a comment on issue #20:
Motion to finalize with a disposition to merge
This RFC was forgotten for a little while with one piece of unresolved feedback, which has now been resolved. We have been using it de-facto during the time it was open.
Stakeholders sign-off
This effects all Bytecode Alliance projects so I've copied the biggest stakeholder list I could find (#14) and added some new folks. I apologize if I missed anyone, I am happy to add folks.
Arm
- [ ] @akirilov-arm
- [ ] @sparker-arm
DFINITY
- [ ] @granstrom
Embark Studios
- [ ] @bnjbvr
- [ ] @repi
Fastly
- [x] @cfallin
- [ ] @sunfishcode
- [x] @fitzgen
- [x] @pchickey
- [ ] @peterhuene
- [x] @acfoltzer
- [ ] @iximeow
- [ ] @aturon
- [ ] @cratelyn
- [ ] @elliottt
- [x] @jameysharp
Google/Envoy
- [ ] @PiotrSikora
Intel
- [ ] @mingqiusun
- [ ] @abrown
- [ ] @jlb6740
Microsoft
- [x] @squillace
Fermyon
- [ ] @bacongobbler
- [ ] @radu-matei
Mozilla
- [ ] @julian-seward1
- [ ] @yurydelendik
IBM
- [ ] @uweigand
wasmCloud
- [ ] @autodidaddict
Unaffiliated
- [ ] @tschneidereit
- [ ] @bjorn3
fitzgen commented on issue #20:
As per the RFC process this RFC is entering its 10 day final comment period.
If no objections have been raised by 2022-08-28, we will merge this RFC.
cfallin edited a comment on issue #20:
Motion to finalize with a disposition to merge
This RFC was forgotten for a little while with one piece of unresolved feedback, which has now been resolved. We have been using it de-facto during the time it was open.
Stakeholders sign-off
This effects all Bytecode Alliance projects so I've copied the biggest stakeholder list I could find (#14) and added some new folks. I apologize if I missed anyone, I am happy to add folks.
Arm
- [ ] @akirilov-arm
- [ ] @sparker-arm
DFINITY
- [ ] @granstrom
Embark Studios
- [ ] @bnjbvr
- [ ] @repi
Fastly
- [x] @cfallin
- [ ] @sunfishcode
- [x] @fitzgen
- [x] @pchickey
- [ ] @peterhuene
- [x] @acfoltzer
- [ ] @iximeow
- [ ] @aturon
- [ ] @cratelyn
- [ ] @elliottt
- [x] @jameysharp
Google/Envoy
- [ ] @PiotrSikora
Intel
- [ ] @mingqiusun
- [ ] @abrown
- [ ] @jlb6740
Microsoft
- [x] @squillace
Fermyon
- [ ] @bacongobbler
- [x] @radu-matei
Mozilla
- [ ] @julian-seward1
- [ ] @yurydelendik
IBM
- [ ] @uweigand
wasmCloud
- [ ] @autodidaddict
Unaffiliated
- [ ] @tschneidereit
- [ ] @bjorn3
bjorn3 commented on issue #20:
@tschneidereit should be listed in the Fastly section, right?
fitzgen edited a comment on issue #20:
Motion to finalize with a disposition to merge
This RFC was forgotten for a little while with one piece of unresolved feedback, which has now been resolved. We have been using it de-facto during the time it was open.
Stakeholders sign-off
This effects all Bytecode Alliance projects so I've copied the biggest stakeholder list I could find (#14) and added some new folks. I apologize if I missed anyone, I am happy to add folks.
Arm
- [ ] @akirilov-arm
- [ ] @sparker-arm
DFINITY
- [ ] @granstrom
Embark Studios
- [ ] @bnjbvr
- [ ] @repi
Fastly
- [x] @cfallin
- [ ] @sunfishcode
- [x] @fitzgen
- [x] @pchickey
- [ ] @peterhuene
- [x] @acfoltzer
- [ ] @iximeow
- [ ] @aturon
- [ ] @cratelyn
- [ ] @elliottt
- [x] @jameysharp
Google/Envoy
- [ ] @PiotrSikora
Intel
- [ ] @mingqiusun
- [ ] @abrown
- [ ] @jlb6740
Microsoft
- [x] @squillace
Fermyon
- [ ] @bacongobbler
- [x] @radu-matei
Mozilla
- [ ] @julian-seward1
- [ ] @yurydelendik
IBM
- [ ] @uweigand
wasmCloud
- [ ] @autodidaddict
Unaffiliated
- [ ] @tschneidereit
- [x] @bjorn3
fitzgen edited a comment on issue #20:
Motion to finalize with a disposition to merge
This RFC was forgotten for a little while with one piece of unresolved feedback, which has now been resolved. We have been using it de-facto during the time it was open.
Stakeholders sign-off
This effects all Bytecode Alliance projects so I've copied the biggest stakeholder list I could find (#14) and added some new folks. I apologize if I missed anyone, I am happy to add folks.
Arm
- [ ] @akirilov-arm
- [ ] @sparker-arm
DFINITY
- [ ] @granstrom
Embark Studios
- [ ] @bnjbvr
- [ ] @repi
Fastly
- [x] @cfallin
- [ ] @sunfishcode
- [x] @fitzgen
- [x] @pchickey
- [ ] @peterhuene
- [x] @acfoltzer
- [ ] @iximeow
- [ ] @aturon
- [ ] @cratelyn
- [ ] @elliottt
- [x] @jameysharp
Google/Envoy
- [ ] @PiotrSikora
Intel
- [ ] @mingqiusun
- [x] @abrown
- [ ] @jlb6740
Microsoft
- [x] @squillace
Fermyon
- [ ] @bacongobbler
- [x] @radu-matei
Mozilla
- [ ] @julian-seward1
- [ ] @yurydelendik
IBM
- [ ] @uweigand
wasmCloud
- [ ] @autodidaddict
Unaffiliated
- [ ] @tschneidereit
- [x] @bjorn3
pchickey deleted a comment on issue #20:
@tschneidereit should be listed in the Fastly section, right?
pchickey edited a comment on issue #20:
Motion to finalize with a disposition to merge
This RFC was forgotten for a little while with one piece of unresolved feedback, which has now been resolved. We have been using it de-facto during the time it was open.
Stakeholders sign-off
This effects all Bytecode Alliance projects so I've copied the biggest stakeholder list I could find (#14) and added some new folks. I apologize if I missed anyone, I am happy to add folks.
Arm
- [ ] @akirilov-arm
- [ ] @sparker-arm
DFINITY
- [ ] @granstrom
Embark Studios
- [ ] @bnjbvr
- [ ] @repi
Fastly
- [x] @cfallin
- [ ] @sunfishcode
- [x] @fitzgen
- [x] @pchickey
- [ ] @peterhuene
- [x] @acfoltzer
- [ ] @iximeow
- [ ] @aturon
- [ ] @cratelyn
- [ ] @elliottt
- [x] @jameysharp
Google/Envoy
- [ ] @PiotrSikora
Intel
- [ ] @mingqiusun
- [x] @abrown
- [x] @jlb6740
Microsoft
- [x] @squillace
Fermyon
- [ ] @bacongobbler
- [x] @radu-matei
Mozilla
- [ ] @julian-seward1
- [ ] @yurydelendik
IBM
- [ ] @uweigand
wasmCloud
- [ ] @autodidaddict
Unaffiliated
- [ ] @tschneidereit
- [x] @bjorn3
bnjbvr edited a comment on issue #20:
Motion to finalize with a disposition to merge
This RFC was forgotten for a little while with one piece of unresolved feedback, which has now been resolved. We have been using it de-facto during the time it was open.
Stakeholders sign-off
This effects all Bytecode Alliance projects so I've copied the biggest stakeholder list I could find (#14) and added some new folks. I apologize if I missed anyone, I am happy to add folks.
Arm
- [ ] @akirilov-arm
- [ ] @sparker-arm
DFINITY
- [ ] @granstrom
Embark Studios
- [x] @bnjbvr
- [ ] @repi
Fastly
- [x] @cfallin
- [ ] @sunfishcode
- [x] @fitzgen
- [x] @pchickey
- [ ] @peterhuene
- [x] @acfoltzer
- [ ] @iximeow
- [ ] @aturon
- [ ] @cratelyn
- [ ] @elliottt
- [x] @jameysharp
Google/Envoy
- [ ] @PiotrSikora
Intel
- [ ] @mingqiusun
- [x] @abrown
- [x] @jlb6740
Microsoft
- [x] @squillace
Fermyon
- [ ] @bacongobbler
- [x] @radu-matei
Mozilla
- [ ] @julian-seward1
- [ ] @yurydelendik
IBM
- [ ] @uweigand
wasmCloud
- [ ] @autodidaddict
Unaffiliated
- [ ] @tschneidereit
- [x] @bjorn3
pchickey edited a comment on issue #20:
Motion to finalize with a disposition to merge
This RFC was forgotten for a little while with one piece of unresolved feedback, which has now been resolved. We have been using it de-facto during the time it was open.
Stakeholders sign-off
This effects all Bytecode Alliance projects so I've copied the biggest stakeholder list I could find (#14) and added some new folks. I apologize if I missed anyone, I am happy to add folks.
Arm
- [ ] @akirilov-arm
- [ ] @sparker-arm
DFINITY
- [ ] @granstrom
Embark Studios
- [x] @bnjbvr
- [ ] @repi
Fastly
- [x] @cfallin
- [ ] @sunfishcode
- [x] @fitzgen
- [x] @pchickey
- [ ] @peterhuene
- [x] @acfoltzer
- [ ] @iximeow
- [ ] @aturon
- [ ] @cratelyn
- [ ] @elliottt
- [x] @jameysharp
Google/Envoy
- [ ] @PiotrSikora
Intel
- [ ] @mingqiusun
- [x] @abrown
- [x] @jlb6740
Microsoft
- [x] @squillace
Fermyon
- [ ] @bacongobbler
- [x] @radu-matei
Mozilla
- [ ] @julian-seward1
- [ ] @yurydelendik
IBM
- [x] @uweigand
wasmCloud
- [ ] @autodidaddict
Unaffiliated
- [ ] @tschneidereit
- [x] @bjorn3
fitzgen commented on issue #20:
The final comment period has elapsed without any objections, so I'm going to merge this!
Last updated: Nov 22 2024 at 16:03 UTC