Skip to content

Verify PSIRT mailbox and CVE assignment operational readiness #1144

Description

@justinjoy

Scope

Operationally verify that the published security contact is monitored as a PSIRT intake channel and that maintainers can request CVE IDs through the documented MITRE/GitHub CNA path. Verify the published GPG key remains usable for encrypted disclosures.

Discovery context

Issue #753 requires a documented PSIRT/CVE process and support policy. During Architect/Critic review, the repository evidence confirmed that inquiry@cleverplant.com is published, but did not prove live mailbox ownership/monitoring, a designated CVE assignee, or an end-to-end encrypted-report exercise. These are operational facts that should not be invented in documentation.

Acceptance criteria

  • Maintainer confirms the mailbox receives a test security report and records the on-call/triage owner privately.
  • Maintainer records the authorized CVE assignment path and completes a test request or documents the CNA/MITRE response.
  • The published GPG fingerprint encrypts and decrypts a test message successfully.
  • Update SECURITY.md or the release runbook with only the verified operational details.

Priority and dependency

Security/release blocker follow-up. Depends on the public policy documentation in #753, but requires maintainer or service-owner access that is not available from repository code alone.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions