Skip to content

Add FreeRTOS Labs project notice to SECURITY.md#85

Open
AniruddhaKanhere wants to merge 1 commit into
FreeRTOS:mainfrom
AniruddhaKanhere:labs-security-md-notice
Open

Add FreeRTOS Labs project notice to SECURITY.md#85
AniruddhaKanhere wants to merge 1 commit into
FreeRTOS:mainfrom
AniruddhaKanhere:labs-security-md-notice

Conversation

@AniruddhaKanhere

Copy link
Copy Markdown
Member

This prepends a short notice to the existing .github/SECURITY.md clarifying that this repository is a FreeRTOS Labs project and linking to the FreeRTOS Labs introduction page.

Labs projects are functional but may be incomplete or experimental and are not part of the actively maintained, released FreeRTOS libraries. The notice asks reporters to consider those documented Labs limitations before concluding that an observed behavior is an issue in a released library. The existing reporting section is left unchanged.

Clarifies that this is a FreeRTOS Labs project and links to the Labs
introduction page, so observed limitations of an experimental Labs
project are not mistaken for issues in a released library.
Comment thread .github/SECURITY.md
Comment on lines +3 to +8
This repository is a **FreeRTOS Labs** project. As described on the
[FreeRTOS Labs introduction page](https://www.freertos.org/Documentation/03-Libraries/05-FreeRTOS-labs/01-Introduction),
Labs projects are functional but may be incomplete, experimental, or provided primarily for
open-source community interest. They are **not** part of the actively maintained, released
FreeRTOS libraries. Please consider the limitations described on the Labs page before
concluding that an observed behavior is a security vulnerability.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd prefer encouraging healthy testing and validation practices rather than discouraging reports

Suggested change
This repository is a **FreeRTOS Labs** project. As described on the
[FreeRTOS Labs introduction page](https://www.freertos.org/Documentation/03-Libraries/05-FreeRTOS-labs/01-Introduction),
Labs projects are functional but may be incomplete, experimental, or provided primarily for
open-source community interest. They are **not** part of the actively maintained, released
FreeRTOS libraries. Please consider the limitations described on the Labs page before
concluding that an observed behavior is a security vulnerability.
This repository is a **FreeRTOS Labs** project. As described on the
[FreeRTOS Labs introduction page](https://www.freertos.org/Documentation/03-Libraries/05-FreeRTOS-labs/01-Introduction),
Labs projects are functional but may be incomplete, experimental, or provided primarily for
open-source community interest. They are **not** part of the actively maintained, released
FreeRTOS libraries.
As our customer, any applications you integrate this lab project into should be thoroughly tested, secured, and optimized according to your business's security standards & policies before deploying to production or handling production workloads.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants