Pursuant to the Haskell Foundation Tech Proposal #37, the Haskell Foundation is establishing a Security Advisory Database for the Haskell ecosystem, and assembling the Security Response Team (SRT) who will manage it.
We are now formally calling for applications for the initial SRT. People from the Haskell community with information security experience are encouraged to apply. This is an opportunity to have a large impact on the practice of Haskell programming going forward.
Security Response Team responsibilities
The general responsibilities of the SRT are:
-
Manage the Haskell Security Advisory Database, on behalf of the Haskell community and the Haskell Foundation.
-
Triage and assess incoming security reports or proposed/candidate security advisories.
-
Assist reporters to determine CVSS scores and CWE values for confirmed security issues.
-
Communicate with package maintainers and the community to promote the timely resolution of reported security issues.
-
Ensure the security advisory data are useful for downstream security tooling. (Development of