...
Issue Levels
Issues that are deemed high, medium or low will be addressed as part of the planning for the next EdgeX release.
EdgeX grades security issues on the CVSS (Common Vulnerability Scoring System) scale. The four levels are critical, high, medium and low level issues.
SIR Team Member Qualifications:
The SIR team member brings security knowledge, product experience to comprehend issue ramifications, has contributed to one or more EdgeX components, passion, a can-do attitude. She/he must honour the requirement to responsibly disclose a security issues. Each issue needs to be triaged, a clear understanding obtained, its criticality determined, and more often than not one or more members of the EdgeX community approached to develop a fix or workaround. The SIR team will work with QA and product definition teams to test fixes, determine release timeline and more.
Release Specific Known Issues
...