Skip to content

Enforce backporting of security patches. #6131

@ben-polinsky

Description

@ben-polinsky

Feature

We should automate backporting of CVE PRs.

As a part of this:

  • We need to standardize a PR format for CVE fixes:
    • PR title should be standard
    • PR should have a CVE tag
    • PRs should only contain CVE fixes
  • We should create a Github action that will backport CVE fixes to the pervious version
  • We should have an enforcement/automation that that action is ran on CVE PRs

Additional Info

How many versions should be backported too?

Metadata

Metadata

Labels

buildologyIssues related to process, tooling or CI/CD pipelinessecurity

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions