Dear all,
As part of the Eclipse Foundation's participation in Anthropic's Project Glasswing, the Eclipse Foundation Security Team is currently running a vulnerability scanning campaign across Eclipse projects, and more private vulnerability reports will be opened in the coming weeks.
These reports are automatically assigned to the people listed as your project's Security Team in the PMI. If you haven't configured this team, it defaults to all committers, which may cause reports to reach too many people. You can read more about the role of the Project Security Team in the Eclipse Project Handbook: https://www.eclipse.org/projects/handbook/#projects-security-team
We'd kindly ask each project to take a few minutes to:
1. Open your project's page in the PMI (https://projects.eclipse.org/) and review the Security Team setting.
2. Keep it to a small group of committers who will actually triage and handle vulnerability reports (typically 2 to 4 people). Additional committers can always be brought in after the initial triage if needed.
3. Make sure the people listed are active and reachable.
This helps us route reports to the right people, keeps notifications manageable for everyone else, and helps you respond to issues faster.
Questions about project security teams can be sent to security@xxxxxxxxxxxxxxxxxxxxxx or discussed publicly in the Eclipse CSI GitHub Discussions: https://github.com/orgs/eclipse-csi/discussions
Thank you for your continued commitment to the security of the Eclipse ecosystem.
Eclipse Foundation Security Team