当前位置:首页 > 报告详情

zds-2023-06-27-security.pdf

上传人: 2*** 编号:144819 2023-10-28 23页 402.75KB

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
The Zephyr Project is an open-source project that supports various architectures and features a large codebase written in C. It has a Security Committee and a Security Working Group to ensure the project's security. The project follows security standards such as ETSI EN 303-645, FIPS 140-3, and SP 800-128. The lifecycle of a vulnerability in Zephyr involves keeping reports private for a 90-day embargo period to allow time for affected parties to mitigate risks before the vulnerability is publicly disclosed. This process includes reporting, triage, fixing, and release management. Key points: - Zephyr has over 1.3 million lines of C code and 20 million lines of code in modules. - The Security Committee meets every two weeks, and the Security Working Group is open to anyone. - The project has a threat model to understand and treat vulnerabilities differently from bugs. - Zephyr has a process for backports to address vulnerabilities in older versions of the software. - The project is working on unifying cryptography libraries and handling vulnerabilities in third-party code. - Concerns include automating vulnerability detection and managing module interdependencies.
"Zephyr项目如何处理安全漏洞?" "Zephyr项目中的加密库如何统一?" "如何改进Zephyr项目的漏洞报告和修复流程?"
客服
商务合作
小程序
服务号
折叠