


















Django has a long history of responsible security practices: a dedicated, private security mailing list, clear advisory policies, and predictable security releases. Even so, we relied on external organizations to assign CVE IDs (Common Vulnerabilities and Exposures). This sometimes introduced administrative delays and extra coordination overhead.
Becoming a CNA (CVE Numbering Authority) allows the DSF to:
The process began with internal discussions within the DSF Board and Django Security Team. We evaluated:
After confirming that our policies were mature and that the administrative workload would be manageable, we initiated the CNA application with MITRE.
MITRE requires that new CNAs document their security processes and demonstrate that they can meet CNA obligations. Our preparation included:
Reviewing and updating the Django Security Policy.
Mapping our existing workflows to MITRE's CNA rules, including:
Defining the scope of the CNA:
Ensuring we had private communication channels and documented procedures for confidential handling.
Drafting the required procedural documentation for MITRE.
Most of the work here was not about creating new processes but about articulating long standing Django practices in the format MITRE expects.
Once our initial documentation was accepted, MITRE scheduled us for CNA onboarding training. This covered:
We also completed MITRE's required CNA onboarding exercises. As part of this process, we worked through sample security reports and demonstrated how we would determine CVE assignments, including cases where multiple CVEs may or may not be warranted for a single report.
After MITRE approved our documentation, training, and exercise submissions, the DSF was formally granted CNA status. The announcements steps were:
A few procedural insights for other projects considering CNA status:
For most contributors and users, nothing changes. Django will continue to follow its established process for receiving reports, coordinating fixes, and publishing security releases.
The difference is that the DSF can now assign CVE IDs directly, which simplifies coordination and allows us to publish advisories with fewer external dependencies.
This work was led by Django Fellows Natalia Bidart and Jacob Walls, with support from the Django Security Team and the DSF Board. We are grateful to MITRE for their guidance during the onboarding process.
If you have questions about Django's CNA scope or security process, contact the Django Security Team.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。