Skip to content

RFC: AI Security Bug Reporting Policy - #54

Open
makubacki wants to merge 1 commit into
OpenDevicePartnership:mainfrom
makubacki:update_security_policy_for_ai
Open

RFC: AI Security Bug Reporting Policy#54
makubacki wants to merge 1 commit into
OpenDevicePartnership:mainfrom
makubacki:update_security_policy_for_ai

Conversation

@makubacki

Copy link
Copy Markdown
Contributor

Updates the ODP security policy to account for security bugs found using AI tools to make handling such findings consistent and efficient across the organization.

@makubacki makubacki self-assigned this Aug 7, 2026
Copilot AI lite review requested due to automatic review settings August 7, 2026 18:17
@makubacki
makubacki requested a review from a team as a code owner August 7, 2026 18:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a new RFC proposing updates to the Open Device Partnership’s security policy guidance for handling vulnerabilities identified with AI assistance, aiming to treat such findings as public information to reduce embargo-related risk and delays.

Changes:

  • Adds a new RFC document defining the motivation, goals, and requirements for AI-assisted security bug reporting.
  • Includes “prior art” and a proposed SECURITY.md template update that adds a “Security Bugs Found Using AI” section.
  • Documents alternatives and explicitly scopes out code/design considerations (N/A sections).
Suppressed comments (2)

rfc/0000-ai-security-policy.md:139

  • In GitHub’s branding, “GitHub” should be capitalized as such (currently “Github”).
To do so, please reach out in the form of a
[Github Security Advisory](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities).

rfc/0000-ai-security-policy.md:40

  • Typo/consistency: “AI assisted” should be hyphenated as the compound adjective “AI-assisted” to match usage elsewhere (e.g., “AI-assisted discovery”).

- The template must state that AI assisted findings are treated as public information.
- Reporters should still avoid posting public information to reproduce the bug, but be ready to offer it privately
  on request.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread rfc/0000-ai-security-policy.md
Comment thread rfc/0000-ai-security-policy.md
Comment thread rfc/0000-ai-security-policy.md Outdated
@makubacki
makubacki requested a review from Flickdm August 7, 2026 18:19
@makubacki
makubacki force-pushed the update_security_policy_for_ai branch from 894a72a to fc001a3 Compare August 7, 2026 18:22
Updates the ODP security policy to account for security bugs found
using AI tools to make handling such findings consistent and efficient
across the organization.

Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
@makubacki
makubacki force-pushed the update_security_policy_for_ai branch from fc001a3 to 74a3283 Compare August 7, 2026 18:24
Comment on lines +159 to +160
people around the same time and delays addressing the issue increase the window
of time others are aware of the problem while a fix is not available. Because of

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
people around the same time and delays addressing the issue increase the window
of time others are aware of the problem while a fix is not available. Because of
people around the same time and delays addressing the issue by increasing the window
of time others are aware of the problem while a fix is not available. Because of

I think you mean this, but that sentence has gotten quite long with multiple clauses, I'd consider splitting into multiple sentences.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants